From owner-freebsd-security@FreeBSD.ORG Wed Sep 29 23:50:44 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8D29416A4CE for ; Wed, 29 Sep 2004 23:50:44 +0000 (GMT) Received: from VARK.MIT.EDU (VARK.MIT.EDU [18.95.3.179]) by mx1.FreeBSD.org (Postfix) with ESMTP id 419EE43D41 for ; Wed, 29 Sep 2004 23:50:44 +0000 (GMT) (envelope-from das@FreeBSD.ORG) Received: from VARK.MIT.EDU (localhost [127.0.0.1]) by VARK.MIT.EDU (8.13.1/8.12.10) with ESMTP id i8TNoUxE031896; Wed, 29 Sep 2004 19:50:30 -0400 (EDT) (envelope-from das@FreeBSD.ORG) Received: (from das@localhost) by VARK.MIT.EDU (8.13.1/8.12.10/Submit) id i8TNoTRO031895; Wed, 29 Sep 2004 19:50:29 -0400 (EDT) (envelope-from das@FreeBSD.ORG) Date: Wed, 29 Sep 2004 19:50:29 -0400 From: David Schultz To: David Pick Message-ID: <20040929235029.GA31828@VARK.MIT.EDU> Mail-Followup-To: David Pick , Deepak Jain , freebsd-security@FreeBSD.ORG, dwbear75@gmail.com, cjclark@alum.mit.edu, Alexander Langer References: <4159EABF.3030004@ai.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: cc: freebsd-security@FreeBSD.ORG cc: Alexander Langer cc: dwbear75@gmail.com cc: cjclark@alum.mit.edu cc: Deepak Jain Subject: Re: Kernel-loadable Root Kits X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Sep 2004 23:50:44 -0000 On Wed, Sep 29, 2004, David Pick wrote: > 6) securelevel *is* a great thing but sysadmins are tied to the > hierarchy of levels chosen by the project, and one size does *not* > fit all. As a more general mechanism I would suggest that there > is a kernel-build option for *each* facility that can be locked > by securelevel, which geves the level at which that facility > becomes locked. Great idea. See mac(4).