⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 mac-lomac.html

📁 FreeBSD操作系统的详细使用手册
💻 HTML
字号:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta name="generator" content="HTML Tidy, see www.w3.org" /><title>The MAC LOMAC Module</title><meta name="GENERATOR" content="Modular DocBook HTML Stylesheet Version 1.7" /><link rel="HOME" title="FreeBSD 使用手册" href="index.html" /><link rel="UP" title="Mandatory Access Control" href="mac.html" /><link rel="PREVIOUS" title="The MAC Biba Module" href="mac-biba.html" /><link rel="NEXT" title="Implementing a Secure Environment with MAC"href="mac-implementing.html" /><link rel="STYLESHEET" type="text/css" href="docbook.css" /><meta http-equiv="Content-Type" content="text/html; charset=GB2312" /></head><body class="SECT1" bgcolor="#FFFFFF" text="#000000" link="#0000FF" vlink="#840084"alink="#0000FF"><div class="NAVHEADER"><table summary="Header navigation table" width="100%" border="0" cellpadding="0"cellspacing="0"><tr><th colspan="3" align="center">FreeBSD 使用手册</th></tr><tr><td width="10%" align="left" valign="bottom"><a href="mac-biba.html"accesskey="P">后退</a></td><td width="80%" align="center" valign="bottom">章 15. Mandatory Access Control</td><td width="10%" align="right" valign="bottom"><a href="mac-implementing.html"accesskey="N">前进</a></td></tr></table><hr align="LEFT" width="100%" /></div><div class="SECT1"><h1 class="SECT1"><a id="MAC-LOMAC" name="MAC-LOMAC">15.13. The MAC LOMAC Module</a></h1><p>Module name: <tt class="FILENAME">mac_lomac.ko</tt></p><p>Kernel configuration line: <var class="LITERAL">options MAC_LOMAC</var></p><p>Boot option: <var class="LITERAL">mac_lomac_load="YES"</var></p><p>Unlike the <acronym class="ACRONYM">MAC</acronym> Biba policy, the <spanclass="CITEREFENTRY"><span class="REFENTRYTITLE">mac_lomac</span>(4)</span> policypermits access to lower integrity objects only after decreasing the integrity level tonot disrupt any integrity rules.</p><p>The <acronym class="ACRONYM">MAC</acronym> version of the Low-watermark integritypolicy, not to be confused with the older <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">lomac</span>(4)</span> implementation, works almost identically toBiba but with the exception of using floating labels to support subject demotion via anauxiliary grade compartment. This secondary compartment takes the form of <varclass="LITERAL">[auxgrade]</var>. When assigning a lomac policy with an auxiliary grade,it should look a little bit like: <var class="LITERAL">lomac/10[2]</var> where the numbertwo (2) is the auxiliary grade.</p><p>The <acronym class="ACRONYM">MAC</acronym> LOMAC policy relies on the ubiquitouslabeling of all system objects with integrity labels, permitting subjects to read fromlow integrity objects and then downgrading the label on the subject to prevent futurewrites to high integrity objects. This is the <var class="LITERAL">[auxgrade]</var>option discussed above, thus the policy may provide for greater compatibility and requireless initial configuration than Biba.</p><div class="SECT2"><h2 class="SECT2"><a id="AEN22476" name="AEN22476">15.13.1. Examples</a></h2><p>Like the Biba and <acronym class="ACRONYM">MLS</acronym> policies; the <ttclass="COMMAND">setfmac</tt> and <tt class="COMMAND">setpmac</tt> utilities may be usedto place labels on system objects:</p><pre class="SCREEN"><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">setfmac /usr/home/trhodes lomac/high[low]</kbd><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">getfmac /usr/home/trhodes</kbd> lomac/high[low]</pre><p>Notice the auxiliary grade here is <var class="LITERAL">low</var>, this is a featureprovided only by the <acronym class="ACRONYM">MAC</acronym> LOMAC policy.</p></div></div><div class="NAVFOOTER"><hr align="LEFT" width="100%" /><table summary="Footer navigation table" width="100%" border="0" cellpadding="0"cellspacing="0"><tr><td width="33%" align="left" valign="top"><a href="mac-biba.html"accesskey="P">后退</a></td><td width="34%" align="center" valign="top"><a href="index.html"accesskey="H">起点</a></td><td width="33%" align="right" valign="top"><a href="mac-implementing.html"accesskey="N">前进</a></td></tr><tr><td width="33%" align="left" valign="top">The MAC Biba Module</td><td width="34%" align="center" valign="top"><a href="mac.html"accesskey="U">上一级</a></td><td width="33%" align="right" valign="top">Implementing a Secure Environment withMAC</td></tr></table></div></body></html>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -