From owner-svn-doc-head@FreeBSD.ORG Sun Nov 17 05:21:12 2013 Return-Path: Delivered-To: svn-doc-head@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 2F825BE9; Sun, 17 Nov 2013 05:21:12 +0000 (UTC) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 0DCB22957; Sun, 17 Nov 2013 05:21:12 +0000 (UTC) Received: from svn.freebsd.org ([127.0.1.70]) by svn.freebsd.org (8.14.7/8.14.7) with ESMTP id rAH5LBCr040158; Sun, 17 Nov 2013 05:21:11 GMT (envelope-from trhodes@svn.freebsd.org) Received: (from trhodes@localhost) by svn.freebsd.org (8.14.7/8.14.5/Submit) id rAH5LBMQ040157; Sun, 17 Nov 2013 05:21:11 GMT (envelope-from trhodes@svn.freebsd.org) Message-Id: <201311170521.rAH5LBMQ040157@svn.freebsd.org> From: Tom Rhodes Date: Sun, 17 Nov 2013 05:21:11 +0000 (UTC) To: doc-committers@freebsd.org, svn-doc-all@freebsd.org, svn-doc-head@freebsd.org Subject: svn commit: r43200 - head/en_US.ISO8859-1/books/handbook/mac X-SVN-Group: doc-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-doc-head@freebsd.org X-Mailman-Version: 2.1.16 Precedence: list List-Id: SVN commit messages for the doc tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 17 Nov 2013 05:21:12 -0000 Author: trhodes Date: Sun Nov 17 05:21:11 2013 New Revision: 43200 URL: http://svnweb.freebsd.org/changeset/doc/43200 Log: Collapse the various policy discussions into a single section. Discussed with: dru Modified: head/en_US.ISO8859-1/books/handbook/mac/chapter.xml Modified: head/en_US.ISO8859-1/books/handbook/mac/chapter.xml ============================================================================== --- head/en_US.ISO8859-1/books/handbook/mac/chapter.xml Sat Nov 16 22:58:33 2013 (r43199) +++ head/en_US.ISO8859-1/books/handbook/mac/chapter.xml Sun Nov 17 05:21:11 2013 (r43200) @@ -763,7 +763,14 @@ test: biba/high option is called . - + + Available MAC Policies + + &os; includes a group of policies that will cover + most security requirements. Each policy is discussed + below. + + The MAC See Other UIDs Policy @@ -816,9 +823,9 @@ test: biba/high may not be set. - + - + The MAC BSD Extended Policy @@ -855,7 +862,7 @@ test: biba/high module as incorrect use could block access to certain parts of the file system. - + Examples After the &man.mac.bsdextended.4; module has been loaded, @@ -895,10 +902,10 @@ test: biba/high For more information, refer to &man.mac.bsdextended.4; and &man.ugidfw.8; - - + + - + The MAC Interface Silencing Policy @@ -947,9 +954,9 @@ test: biba/high security/aide to automatically block network traffic if it finds new or altered files in protected directories. - + - + The MAC Port Access Control List Policy @@ -1035,7 +1042,7 @@ net.inet.ip.portrange.reservedhigh=0See the examples below or refer to &man.mac.portacl.4; for further information. - + Examples Since the root user should not be @@ -1060,10 +1067,10 @@ net.inet.ip.portrange.reservedhigh=0&prompt.root; sysctl security.mac.portacl.rules=uid:1001:tcp:110,uid:1001:tcp:995 - - + + - + The MAC Partition Policy @@ -1113,7 +1120,7 @@ net.inet.ip.portrange.reservedhigh=0insecure class will stay in the partition/13 label. - + Examples The following command will display the partition label @@ -1143,10 +1150,10 @@ net.inet.ip.portrange.reservedhigh=0 - - + + - + The MAC Multi-Level Security Module @@ -1277,7 +1284,7 @@ net.inet.ip.portrange.reservedhigh=0setfmac. This method will be explained after all policies are covered. - + Planning Mandatory Sensitivity When using the MLS policy module, an administrator plans @@ -1302,10 +1309,10 @@ net.inet.ip.portrange.reservedhigh=0 - - + + - + The MAC Biba Module @@ -1419,7 +1426,7 @@ net.inet.ip.portrange.reservedhigh=0getfmac test test: biba/low - + Planning Mandatory Integrity Integrity, which is different from sensitivity, guarantees @@ -1457,10 +1464,10 @@ test: biba/low development and test machine, and a source code repository. A less useful implementation would be a personal workstation, a machine used as a router, or a network firewall. - - + + - + The MAC LOMAC Module @@ -1495,7 +1502,7 @@ test: biba/low policy may provide for greater compatibility and require less initial configuration than Biba. - + Examples Like the Biba and MLS policies, @@ -1508,7 +1515,8 @@ test: biba/low The auxiliary grade low is a feature provided only by the MAC LOMAC policy. - + +