<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tomoyo GUI</title>
	<atom:link href="http://dodonov.net/blog/2009/07/06/tomoyo-gui/feed/" rel="self" type="application/rss+xml" />
	<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/</link>
	<description>My view on technology, open-source, Linux and other cool things.</description>
	<lastBuildDate>Thu, 17 May 2012 13:22:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Pawel Stolowski</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-17245</link>
		<dc:creator>Pawel Stolowski</dc:creator>
		<pubDate>Sun, 07 Mar 2010 17:44:40 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-17245</guid>
		<description>&lt;p&gt;You don&#039;t need to check all the possible execution paths leading to specific daemon/executable - you just need an &#039;initialize_domain&#039; rule in exception_policy.conf. Just say &#039;initialize_domain /sbin/httpd&#039; and then all the rules applied to /sbin/httpd/ domain will take effect no matter how httpd was executed.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You don&#8217;t need to check all the possible execution paths leading to specific daemon/executable &#8211; you just need an &#8216;initialize_domain&#8217; rule in exception_policy.conf. Just say &#8216;initialize_domain /sbin/httpd&#8217; and then all the rules applied to /sbin/httpd/ domain will take effect no matter how httpd was executed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mandriva 2010.0 -  </title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-17089</link>
		<dc:creator>Mandriva 2010.0 -  </dc:creator>
		<pubDate>Thu, 05 Nov 2009 10:46:49 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-17089</guid>
		<description>&lt;p&gt;[...]  [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mandriva 2010.0 - Настрой сервер сам</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-17084</link>
		<dc:creator>Mandriva 2010.0 - Настрой сервер сам</dc:creator>
		<pubDate>Tue, 03 Nov 2009 09:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-17084</guid>
		<description>&lt;p&gt;[...] Security Framework вместе с собственной разработкой tomoyo-gui в качестве альтернативы [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Security Framework вместе с собственной разработкой tomoyo-gui в качестве альтернативы [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: News Wave &#187; Релиз Mandriva 2010.0</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-17082</link>
		<dc:creator>News Wave &#187; Релиз Mandriva 2010.0</dc:creator>
		<pubDate>Tue, 03 Nov 2009 07:16:45 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-17082</guid>
		<description>&lt;p&gt;[...] Security Framework вкупе с собственной разработкой tomoyo-gui в качестве замены [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Security Framework вкупе с собственной разработкой tomoyo-gui в качестве замены [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-16910</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Tue, 07 Jul 2009 15:42:42 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-16910</guid>
		<description>&lt;p&gt;That&#039;s the idea :) .&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>That&#8217;s the idea <img src='http://dodonov.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aapgorilla</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-16909</link>
		<dc:creator>aapgorilla</dc:creator>
		<pubDate>Tue, 07 Jul 2009 15:27:11 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-16909</guid>
		<description>&lt;p&gt;Wouldn&#039;t it be a good idea to integrate tomoyo_gui into msec_gui? To have one gui for all security related settings...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it be a good idea to integrate tomoyo_gui into msec_gui? To have one gui for all security related settings&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-16907</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Tue, 07 Jul 2009 12:39:22 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-16907</guid>
		<description>&lt;p&gt;The problem with tomoyo is that the policies do not contain the executable path, but the sequences of execution from kernel until the current executable.&lt;/p&gt;

&lt;p&gt;I thought on using a tree view for all policies, but it leads to confusion. For example, &lt;kernel&gt; /sbin/init could lead to a lot of daemons, each daemon leading to a multitude of applications, and so on. So if we use the treeview, it will require to go about 13 levels deeper to get the application you want. And it also makes harder to find the application you want.&lt;/p&gt;

&lt;p&gt;The ccs-editpolicy simplifies it by trimming the initial path, so it is easier to see. Maybe I&#039;ll follow the same idea.&lt;/p&gt;

&lt;p&gt;Another problem is that the entire policy is contained in the same big policy file. So we cannot, for example, provide specific policy for an RPM inside the package, we&#039;ll have to merge it with the system policy. For example, we cannot set policy for /sbin/httpd - we have to check all the possible execution paths leading to /sbin/httpd (like &lt;kernel&gt; /sbin/init, &lt;kernel&gt; /sbin/init /etc/rc ..., and so on). I was already thinking on it, but nothing is done about this yet.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The problem with tomoyo is that the policies do not contain the executable path, but the sequences of execution from kernel until the current executable.</p>

<p>I thought on using a tree view for all policies, but it leads to confusion. For example, <kernel> /sbin/init could lead to a lot of daemons, each daemon leading to a multitude of applications, and so on. So if we use the treeview, it will require to go about 13 levels deeper to get the application you want. And it also makes harder to find the application you want.</kernel></p>

<p>The ccs-editpolicy simplifies it by trimming the initial path, so it is easier to see. Maybe I&#8217;ll follow the same idea.</p>

<p>Another problem is that the entire policy is contained in the same big policy file. So we cannot, for example, provide specific policy for an RPM inside the package, we&#8217;ll have to merge it with the system policy. For example, we cannot set policy for /sbin/httpd &#8211; we have to check all the possible execution paths leading to /sbin/httpd (like <kernel> /sbin/init, </kernel><kernel> /sbin/init /etc/rc &#8230;, and so on). I was already thinking on it, but nothing is done about this yet.</kernel></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FACORAT Fabrice</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-16905</link>
		<dc:creator>FACORAT Fabrice</dc:creator>
		<pubDate>Tue, 07 Jul 2009 07:12:24 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-16905</guid>
		<description>&lt;p&gt;I have some difficulties understanding the UI.
If I understand correctly :
1st column : . What is it ? When lokking at some policies samples, it seems to be always . Should we show it then ?&lt;/p&gt;

&lt;p&gt;2nd : this is always the same thing. So I guess this is the executable on which we want to apply some policies ?&lt;/p&gt;

&lt;p&gt;3rd column : what is it ? The list of function calls by the 2nd column ? If yes, then we should use a hierarchical tree. Something like this :

    &#124;
    + -- /etc/rc.d/init.d/asusoled
                    &#124;
                    &#124;- /bin/rm
                    &#124;- /bin/sed&lt;/p&gt;

&lt;p&gt;cf also : http://tomoyo.sourceforge.jp/en/1.6.x/tool-editpolicy.html&lt;/p&gt;

&lt;p&gt;Another interesting things which could be interesting :
- ability to save or load a policy for a domain/executable. Some polices sample here : http://tomoyo.sourceforge.jp/cgi-bin/lxr/source/?v=policy-sample
- ability to manage policies by rpm packages: list installed packages on the system, select a package, start learning mode. As we have the list of files in the packages, only the entries ( and their children ) for the files contained in the package will be shown.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I have some difficulties understanding the UI.
If I understand correctly :
1st column : . What is it ? When lokking at some policies samples, it seems to be always . Should we show it then ?</p>

<p>2nd : this is always the same thing. So I guess this is the executable on which we want to apply some policies ?</p>

<p>3rd column : what is it ? The list of function calls by the 2nd column ? If yes, then we should use a hierarchical tree. Something like this :

    |
    + &#8212; /etc/rc.d/init.d/asusoled
                    |
                    |- /bin/rm
                    |- /bin/sed</p>

<p>cf also : <a href="http://tomoyo.sourceforge.jp/en/1.6.x/tool-editpolicy.html" rel="nofollow" onclick="urchinTracker('/outgoing/tomoyo.sourceforge.jp/en/1.6.x/tool-editpolicy.html?referer=');">http://tomoyo.sourceforge.jp/en/1.6.x/tool-editpolicy.html</a></p>

<p>Another interesting things which could be interesting :
- ability to save or load a policy for a domain/executable. Some polices sample here : <a href="http://tomoyo.sourceforge.jp/cgi-bin/lxr/source/?v=policy-sample" rel="nofollow" onclick="urchinTracker('/outgoing/tomoyo.sourceforge.jp/cgi-bin/lxr/source/?v=policy-sample&amp;referer=');">http://tomoyo.sourceforge.jp/cgi-bin/lxr/source/?v=policy-sample</a>
- ability to manage policies by rpm packages: list installed packages on the system, select a package, start learning mode. As we have the list of files in the packages, only the entries ( and their children ) for the files contained in the package will be shown.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bedi</title>
		<link>http://dodonov.net/blog/2009/07/06/tomoyo-gui/comment-page-1/#comment-16900</link>
		<dc:creator>bedi</dc:creator>
		<pubDate>Mon, 06 Jul 2009 16:49:01 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=473#comment-16900</guid>
		<description>&lt;p&gt;hehehehe :D&lt;/p&gt;

&lt;p&gt;Good job doc.!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>hehehehe <img src='http://dodonov.net/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>

<p>Good job doc.!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: dodonov.net @ 2012-05-21 21:23:48 -->
