<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://kernsec.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Linux_Security_Summit_2013%2FAbstracts%2FSchaufler</id>
	<title>Linux Security Summit 2013/Abstracts/Schaufler - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://kernsec.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Linux_Security_Summit_2013%2FAbstracts%2FSchaufler"/>
	<link rel="alternate" type="text/html" href="http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2013/Abstracts/Schaufler&amp;action=history"/>
	<updated>2026-04-20T09:02:19Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2013/Abstracts/Schaufler&amp;diff=3470&amp;oldid=prev</id>
		<title>JamesMorris: New page: == Title ==  Multiple Concurrent Security Models?  Really?  == Presenter ==  Casey Schaufler, Intel  == Abstract ==  This talk will cover the ongoing work to update the Linux Security Modu...</title>
		<link rel="alternate" type="text/html" href="http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2013/Abstracts/Schaufler&amp;diff=3470&amp;oldid=prev"/>
		<updated>2013-08-02T05:39:50Z</updated>

		<summary type="html">&lt;p&gt;New page: == Title ==  Multiple Concurrent Security Models?  Really?  == Presenter ==  Casey Schaufler, Intel  == Abstract ==  This talk will cover the ongoing work to update the Linux Security Modu...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Title ==&lt;br /&gt;
&lt;br /&gt;
Multiple Concurrent Security Models?  Really?&lt;br /&gt;
&lt;br /&gt;
== Presenter ==&lt;br /&gt;
&lt;br /&gt;
Casey Schaufler, Intel&lt;br /&gt;
&lt;br /&gt;
== Abstract ==&lt;br /&gt;
&lt;br /&gt;
This talk will cover the ongoing work to update the&lt;br /&gt;
Linux Security Module (LSM) infrastructure to allow&lt;br /&gt;
multiple concurrent security modules.&lt;br /&gt;
&lt;br /&gt;
The talk starts with a statement of the problem being&lt;br /&gt;
solved, that the existing infrastructure allows only&lt;br /&gt;
a single LSM (plus Yama) to be active at a time. The&lt;br /&gt;
rationale for the current scheme will be discussed as&lt;br /&gt;
well as what has changed so that the new scheme is in&lt;br /&gt;
the works.&lt;br /&gt;
&lt;br /&gt;
The talk continues with a description of the externally&lt;br /&gt;
visible changes and the reasons they've been made.&lt;br /&gt;
The peculiar configuration issues with networking will&lt;br /&gt;
be covered in some detail. The additions in /proc/.../attr&lt;br /&gt;
will be noted.&lt;br /&gt;
&lt;br /&gt;
Next the structure of the stacking mechanism is detailed,&lt;br /&gt;
with special attention to the allocation and freeing of&lt;br /&gt;
security blobs. The handling of networking hooks and&lt;br /&gt;
secids will be examined.&lt;br /&gt;
&lt;br /&gt;
Finally, the current project plan and status will be&lt;br /&gt;
described.&lt;/div&gt;</summary>
		<author><name>JamesMorris</name></author>
	</entry>
</feed>