LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

RHEL certified at EAL4+

RHEL certified at EAL4+

Posted Jun 19, 2007 0:20 UTC (Tue) by jamesm (guest, #2273)
In reply to: RHEL certified at EAL4+ by jd
Parent article: RHEL certified at EAL4+

Please correct me if I'm wrong, but there appears to be no security labeling of memory regions or of network connections.

SELinux provides MAC coverage for shared memory (and indeed all Sysv IPC mechanisms. For networking, there are two forms of external labeling (CIPSO and a new IPsec based scheme), as well as local labeling of packets integrated with iptables. There's also coverage at the socket API layer, so all newtworking is covered, as well as some protocol-specific coverage for things like Unix domain sockets and Netlink.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds