Fedora and CAPP
Posted Dec 11, 2008 14:54 UTC (Thu) by
davecb (subscriber, #1574)
Parent article:
Fedora and CAPP
I fear the CAPP folks haven't read
the Orange Book (Trusted Computer System Evaluation Criteria DOD-5200.28-STD), or
prehaps forgotten that lower-security
processes can write to higher-security ones, but
not the reverse. Any process should be able
to submit audit entries, but only the
audit daemon can decide if they are to
be accepted (;-))
--dave
(
Log in to post comments)