Rule Set Based Access Control (RSBAC) for Linux - Future Goals
Future Goals
There are a few things planned for the future:
- Everlasting: Improve documentation - there are man pages, concept and detail
descriptions, how-tos, examples and other stuff missing (volunteers?)
- Improve recovering from system crashes - it is still possible (though unlikely) to loose
attributes, if system crashed while modifying /rsbac dir.
- Improve attribute access performance, maybe by seperating between file and dir targets.
- Finish user and password management daemon enforcement (AUTH module), inspired by an
idea of Julio Sanchez. Misses a bit of helper stuff, like PAM stubs etc. Kernel part is
finished, though.
- Add administration menus for ACL model
- Include more scan strings into the Malware Scan module
- Further improve Linux security specially as internet server system, addressing special
needs for that. The (improved) Role Compatibility, the AUTH and the new ACL model should
give a good kick to that.
- (Some day) With or without Pretty Secure Linux:
Meet B1 security requirements. Now that MAC categories and secure delete are implemented
the way has shortened, but it is not really urgent though, since Orange Book is a bit out
of date.
Questions, tips, etc.
08-Sep-99, -ao