Re: Possible system call interface for LSM

From: richard offer (offerat_private)
Date: Mon Aug 13 2001 - 13:01:04 PDT

  • Next message: Jesse Pollard: "Re: Possible system call interface for LSM"

    * frm sarnoldat_private "08/13/01 11:56:20 -0700" | sed '1,$s/^/* /'
    *
    * On Sat, Aug 11, 2001 at 01:20:00AM +0000, David Wagner wrote:
    *> Here we would have to tell admins that they can rmmod a LSM, but to
    *> install a new LSM they have to reboot (or else kill all process that
    *> might have used an extended syscall).  The need to reboot every time
    *> you rmmod a LSM seems pretty ugly.
    * 
    * But it does make sense to ask the admins to stop running module-specific
    * applications when changing modules.
    
    You mean like ls or id or sendmail or X or ...... Basically it will boil
    down to having to do a reboot, so why not say it.
    
    
    richard.
    
    
    -----------------------------------------------------------------------
    Richard Offer                     Technical Lead, Trust Technology, SGI
    "Specialization is for insects"
    _______________________________________________________________________
    
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Mon Aug 13 2001 - 13:02:38 PDT