From owner-freebsd-security@FreeBSD.ORG Fri Feb 15 12:49:35 2008 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 118B916A417 for ; Fri, 15 Feb 2008 12:49:35 +0000 (UTC) (envelope-from BORJAMAR@SARENET.ES) Received: from proxypop1.sarenet.es (proxypop1.sarenet.es [194.30.0.99]) by mx1.freebsd.org (Postfix) with ESMTP id B2AC613C4F7 for ; Fri, 15 Feb 2008 12:49:34 +0000 (UTC) (envelope-from BORJAMAR@SARENET.ES) Received: from [127.0.0.1] (matahari.sarenet.es [192.148.167.18]) by proxypop1.sarenet.es (Postfix) with ESMTP id DEEE65D82 for ; Fri, 15 Feb 2008 13:31:06 +0100 (CET) Message-Id: From: Borja Marcos To: freebsd-security@freebsd.org Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit Mime-Version: 1.0 (Apple Message framework v919.2) Date: Fri, 15 Feb 2008 13:31:05 +0100 X-Mailer: Apple Mail (2.919.2) Subject: MAC subsystem problem (FreeBSD 7) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 15 Feb 2008 12:49:35 -0000 Hello, I'm trying to set up a DNS server under FreeBSD using the mac_biba policy. I use to run bind in low-integrity mode, so that neither it or any of its descendants can modify configuration files, etc. With previous FreeBSD versions there was a handy sysctl setting, "security.mac.enforce_socket" that allowed to bypass the MAC restrictions for a socket. I think it's not a bad idea. After all machines can communicate with untrusted nodes over a network. In my opinion, enforcing the mac_biba restrictions so that a network communication with a local process behaves _differently_ than a network communication with a different node is a bad idea. Any reason why this setting has been eliminated? I think that the best solution is to keep it and let the administrator decide. Best regards, Borja.