|
|
Subscribe / Log in / New account

AppArmor set to be merged for 2.6.36

AppArmor set to be merged for 2.6.36

Posted Jul 31, 2010 7:59 UTC (Sat) by jengelh (guest, #33263)
In reply to: AppArmor set to be merged for 2.6.36 by haradats
Parent article: AppArmor set to be merged for 2.6.36

Both Tomoyo and AppArmor are path-based, but what are their actual important differences to warrant including two path-based LSMs?


to post comments

AppArmor set to be merged for 2.6.36

Posted Jul 31, 2010 13:05 UTC (Sat) by haradats (guest, #44782) [Link] (2 responses)

Your question is simple but the answer will not be as simple. First of all, determining "important" issues is not easy (imagine your friend ask you actual important differences between Linux and OpenBSD), secondary the range of features or functionalities might not be the best scale because they will grow, and fair comparison should be made by someone neutral and using both.

I once tried to make a MAC comparison chart for the newcomers and wrote the following chart.
(Some of the items need updates. Most importantly "security goals" for both AppArmor and TOMOYO are obsolete.)

http://tomoyo.sourceforge.jp/wiki-e/?WhatIs#comparison

My personal opinion on the major difference between AppArmor and TOMOYO are AppArmor works on selected programs ("profile") while TOMOYO treat the whole system as sets of process invocation history ("domain").

There will be a Linux security summit as a part of LinuxCon 2010 and MAC developers meet together. ;-) If possible, I will ask their opinions. (It will be great if you can join!)

https://security.wiki.kernel.org/index.php/LinuxSecurityS...

AppArmor set to be merged for 2.6.36

Posted Jul 31, 2010 14:01 UTC (Sat) by jengelh (guest, #33263) [Link] (1 responses)

>There will be a Linux security summit as a part of LinuxCon 2010 and MAC developers meet together. [...] (It will be great if you can join!)

To still appear at LC-NA would require external contribution. But I am in for LC-J.

AppArmor set to be merged for 2.6.36

Posted Jul 31, 2010 22:44 UTC (Sat) by haradats (guest, #44782) [Link]

Though upcoming LC2010 will be a great opportunity, no critical decisions shall be made by just one meeting and its attendees. Proposing a new LSM module and security issues are discussed via LSM mailing list which is opened to everybody. You can browse the archive and join the conversation regardless of your physical location.

http://vger.kernel.org/vger-lists.html#linux-security-module

The merging process is not easy. It took two years for TOMOYO and four years for AppArmor since their first *postings*, which means they have been rejected for those periods.

http://www.slideshare.net/haradats/time-to-glean-mac-for-...

Merging cannot happen by mistakes, so why don't we celebrate AppArmor's new start for the momemnt? :-)


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds