Downgrading labels

Ilmar S. Habibulin ilmar at watson.org
Tue Apr 5 07:11:19 GMT 2005



On Mon, 4 Apr 2005, fergus wrote:

> this would most likley insert the need for a further privilage that
> would allow a process to assign "top level" to it's child processes
> because any process that wished to reduce it's security level would
> have to do this prior to forking or end up with it's child processes
> isolated at a higher security level.

Enforcing strong security policies sometimes reminds me a snake trying to
catch its tail... ;-)
To Unsubscribe: send mail to majordomo at trustedbsd.org
with "unsubscribe trustedbsd-discuss" in the body of the message



More information about the trustedbsd-discuss mailing list