LSS: Kernel security subsystem reports
LSS: Kernel security subsystem reports
Posted Sep 27, 2012 23:57 UTC (Thu) by spender (guest, #23067)In reply to: LSS: Kernel security subsystem reports by spender
Parent article: LSS: Kernel security subsystem reports
Oh, and to clarify, the reason why the capability situation is so ironic is that the SELinux policy developers claim the policies are developed with careful code inspection, yada yada, and yet the cases of granting CAP_DAC_OVERRIDE is something that can only happen in a vanilla kernel (not grsec kernel) using audit2allow to generate policies ;) Whoops!
-Brad