Re: [RFC] [PATCH] file posix capabilities

From: Crispin Cowan
Date: Fri Aug 18 2006 - 22:00:03 EST

Nicholas Miell wrote:
> OTOH, everybody seems to have moved from capability-based security
> models on to TE/RBAC-based security models, so maybe this isn't worth
> the effort?
TE, RBAC, AppArmor, and POSIX.1e Capabilities are all capability-based
systems, in that they all store the security attributes in the principal
(process, program, whatever) rather than the object (the files being
accessed). The difference is in the style of specifying the principals
and objects.


Crispin Cowan, Ph.D.
Director of Software Engineering, Novell
Hack: adroit engineering solution to an unanticipated problem
Hacker: one who is adroit at pounding round pegs into square holes

