From owner-freebsd-questions@FreeBSD.ORG Mon Jun 16 17:40:54 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E8BBB106564A for ; Mon, 16 Jun 2008 17:40:54 +0000 (UTC) (envelope-from wmoran@potentialtech.com) Received: from mail.potentialtech.com (internet.potentialtech.com [66.167.251.6]) by mx1.freebsd.org (Postfix) with ESMTP id B7D058FC1D for ; Mon, 16 Jun 2008 17:40:49 +0000 (UTC) (envelope-from wmoran@potentialtech.com) Received: from vanquish.ws.pitbpa0.priv.collaborativefusion.com (pr40.pitbpa0.pub.collaborativefusion.com [206.210.89.202]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.potentialtech.com (Postfix) with ESMTPSA id 49260EBC09; Mon, 16 Jun 2008 13:40:48 -0400 (EDT) Date: Mon, 16 Jun 2008 13:39:55 -0400 From: Bill Moran To: Jeffrey Goldberg Message-Id: <20080616133955.b1af14c3.wmoran@potentialtech.com> In-Reply-To: References: <1213611664.6398.275.camel@phoenix.blechhirn.net> <20080616082125.7dd23b70.wmoran@potentialtech.com> X-Mailer: Sylpheed 2.4.8 (GTK+ 2.12.9; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: FreeBSD List Subject: Re: Enforce minimal file/ dir permissions X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 16 Jun 2008 17:40:55 -0000 In response to Jeffrey Goldberg : > On Jun 16, 2008, at 7:21 AM, Bill Moran wrote: > > > Look at MAC and the bsdextended module (filesystem firewall): > > http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/mac.html > > http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/mac-bsdextended.html > > I've recently been looking at those myself, and while I think that I > have developed some limited understanding "in principle" about how MAC > works, I need a great deal more practical guidance. Is there some > extended tutorial with cookbook or other resource that will actually > help someone who doesn't fully grok this work out a policy and rules > that will do more good than harm? In my experience, there is a tremendous dearth of information on this topic, and it's not much better on the Linux side where MAC is call "SE Linux". At this time, I think you're going to have to rely on your own experimenting to fully understand how everything works. Hopefully that will improve with time. -- Bill Moran http://www.potentialtech.com