Re: 'Help' text for the capability module

From: Stephen Smalley (sdsat_private)
Date: Tue Aug 12 2003 - 06:10:05 PDT

  • Next message: Ripin Natani: "About Auditing ..."

    On Sat, 2003-08-09 at 11:35, Serge E. Hallyn wrote:
    > The help text for the capability module currently reads:
    > 
    > > This enables the "default" Linux capabilities functionality.
    > > If you are unsure how to answer this question, answer Y.                
    > 
    > Would there be any objection to adding something something like
    > 
    > >
    > > If you plan to also use another security module, do not compile
    > > this module into the kernel.  Compile it as a module, and load
    > > it after loading the other module.  This module will not permit
    > > subsequent loading of others, whereas most other modules will
    > > permit loading of this module after themselves.
    
    In the case of SELinux, we configure both SELinux and capability
    built-in, and the link order in the Makefile ensures that they are
    initialized in the proper order so that SELinux can register first and
    then handle capability as a secondary module.
    
    -- 
    Stephen Smalley <sdsat_private>
    National Security Agency
    
    _______________________________________________
    linux-security-module mailing list
    linux-security-moduleat_private
    http://mail.wirex.com/mailman/listinfo/linux-security-module
    



    This archive was generated by hypermail 2b30 : Tue Aug 12 2003 - 06:10:41 PDT