[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference smurf::dec_mls_plus

Title:dec_mls_plus
Moderator:SMURF::BAT
Created:Mon Nov 29 1993
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:534
Total number of notes:2544

450.0. "Why is AdvFS a problem ?" by CHEFS::HOWLETT_T (Avoiding the cracks in the pavement) Fri Feb 14 1997 09:34

    Hi
    
    	Re ADVFS, Please could you explain to me, why ADVFS is missing
     form MLS+ when it is available in Unix, Is it beacuse you have
     to reengineer it for MLS+ security?
    
    Terri
    
    
    
T.RTitleUserPersonal
Name
DateLines
450.1may have been missing from eftSMURF::BATSegui la tua beatitudineFri Feb 14 1997 12:4126
    (To summarize the exchange below):
    
    In V4.0A it is available as a "single-level" type file system. 
    IOW, AdvFS does have to be modified to make it multi-level, etc., and
    that has not yet been done (funded/scheduled); but that doesn't
    preclude its use.
    
    -----
    
From:	KAMLIA::king "David King USG" 14-FEB-1997 09:21:51.35
To:	bat@dec:.zko.smurf (Segui la tua beatitudine)
CC:	milicia@DEC:.zko.kamlia (Michael A. Milicia USG)
Subj:	Re: Notefile DEC_MLS_PLUS Note 450.0
    
    re: .0
    
Its not missing.  Its just doesn't provide per-file security attributes,
and a command set that supports role separation.

> 	let me get this straight -- you mean you can create
> 	"single-level" (or unlabelled) AdvFs file systems?
> 	(just as you can do with vanilla UFS ones?)

Yes, starting in V4.0A.

DavE
450.2from mikeSMURF::BATSegui la tua beatitudineFri Feb 14 1997 14:3422
From:	KAMLIA::milicia "Michael A. Milicia USG" 14-FEB-1997 09:42:46.01
To:	king@DEC:.zko.kamlia
CC:	bat@dec:.zko.smurf
Subj:	Re: Notefile DEC_MLS_PLUS Note 450.0

In other words, it is supported in MLS+ V4.0A as a 
single-level filesystem.  
Security attributes must be specified
during mount and those attributes will be implicitly 
associated with every object on the filesystem for the
duration of the mount.

As Dave also points out, you must be root (uid 0) to properly
administer AdvFS in MLS+ V4.0A.
Giving a user a set of command auths will not be sufficient.

Adding full multi-level security support to AdvFS 
would indeed require significant engineering changes to the 
filesystem code.

-- Mike
    
450.3more from daveSMURF::BATSegui la tua beatitudineFri Feb 14 1997 14:5011
From: David King USG <king>
Subject: AdvFS
To: thomson (Barbara Thomson UEG Engineering)
Date: Fri, 14 Feb 1997 10:10:52 -0500 (EST)


One thing that may also be worth noting is that the AdvFS GUI
is not supported.  It requires CDE, therefore will not
even install.

DavE