--- Stephen Smalley <sds@private> wrote: > SELinux == flexible MAC architecture OKay, since no one else has, I'll bit on this one. I accept your assertion that SELinux is a flexible MAC architecture. I've understood that since I first saw it in the basement room with the flashing red light in 1999. Not all security policies are Mandatory. There is value in descretionary policies as well. Name one? Supervisor sign-off, dual authorization, program access lists, to name three. Now, I fully expect to hear that: 1. These could be implemented as Mandatory policies 2. No one has ever implemented any of these policies 3. If they did, SELinux would do it better. Casey Schaufler casey@schaufler-ca.com __________________________________ Do you Yahoo!? Yahoo! Small Business - Try our new Resources site http://smallbusiness.yahoo.com/resources/
This archive was generated by hypermail 2.1.3 : Thu May 26 2005 - 10:54:52 PDT