Thread (54 messages) 54 messages, 5 authors, 2021-12-02

Re: [RFC 15/20] capabilities: Introduce CAP_INTEGRITY_ADMIN

From: Stefan Berger <stefanb@linux.ibm.com>
Date: 2021-11-30 17:42:25
Also in: linux-integrity, lkml

On 11/30/21 12:27, Casey Schaufler wrote:
On 11/30/2021 8:06 AM, Stefan Berger wrote:
quoted
From: Denis Semakin <redacted>

This patch introduces CAP_INTEGRITY_ADMIN, a new capability that allows
to setup IMA (Integrity Measurement Architecture) policies per container
for non-root users.
Why not use CAP_MAC_ADMIN? IMA is a mandatory policy. The scope
is system security administration. It seems to fit your needs.
I introduced CAP_MAC_ADMIN for Smack, and believe that IMA using
it would be completely appropriate.
Fine by me. I suppose we could be reusing it later on also for setting 
file extended attributes for IMA?

    Stefan

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help