Rule Set Based Access Control (RSBAC) for Linux - Future Goals
Future Goals
There are a few things planned for the future:
- Everlasting: Improve documentation - there are man pages, concept and detail
descriptions, how-tos, examples and other stuff missing (volunteers?)
- Support for 2.3.99-pre4ff kernels - there have been name lookup changes within
2.3.99-pre4 which make it impossible to support kernels from pre4 onwards without a new
release number.
- PM update and menu based administration
- (Maybe) SPKI certificates to allow working as (anonymous) guest user with certified
privileges, or to temporarily gain extra privileges
- Improve recovering from system crashes - it is still possible (though unlikely) to loose
attributes, if system crashed while modifying /rsbac dir.
- Improve attribute access performance, maybe by seperating between file and dir targets.
- Finish user and password management daemon enforcement (AUTH module), inspired by an
idea of Julio Sanchez. Misses a bit of helper stuff, like PAM stubs etc. Kernel part is
finished, though.
- Further improve Linux security specially as internet server system, addressing special
needs for that. The (improved) Role Compatibility, the AUTH and the ACL model should help
a lot here.
- Change socket object identification, making them permanent to allow real network access
control.
- Some day, if ever: Meet B1 security requirements. Now that MAC categories and secure
delete are implemented the way has shortened, but it is not really urgent though, since
Orange Book is far out of date.
Questions,
tips, etc.
08-Mai-00, -ao