OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Integrating securelevel and kauth(9)

From: Elad Efrat (eladNetBSD.org)
Date: Sat Mar 25 2006 - 13:50:31 CST


YAMAMOTO Takashi wrote:

> sorry, i think i missed the previous discussion.
> can you give me a pointer to it? was it in this thread?
> i'm not sure what's "custom knobs".

Sure, my post on this is available at:

http://mail-index.netbsd.org/tech-security/2006/01/26/0004.html

(it basically suggested that if the admin is interested, he can choose
to have multiple knobs that each controls a different aspect of what
the single kern.securelevel knob controls today)

> maybe.
> because coalescing listeners is merely an optimization,
> it's better to postpone it until we measure performance impacts, i guess.

No problem. Do you have suggestions for what other scopes we might want
to introduce to cover the other aspects of securelevel?

-e.

--
Elad Efrat