Re: [0/4] Proposal of SE-PostgreSQL patches - Mailing list pgsql-hackers

From KaiGai Kohei
Subject Re: [0/4] Proposal of SE-PostgreSQL patches
Date
Msg-id 47DF177B.8040405@ak.jp.nec.com
Whole thread Raw
In response to Re: [0/4] Proposal of SE-PostgreSQL patches  (Josh Berkus <josh@agliodbs.com>)
Responses Re: [0/4] Proposal of SE-PostgreSQL patches
List pgsql-hackers
Josh Berkus wrote:
> KaiGai,
> 
>> The series of patches are the proposal of Security-Enhanced PostgreSQL
>> (SE-PostgreSQL) for the upstreamed PostgreSQL 8.4 development cycle.
> 
> Since I'm (Finally!) expecting the TrustedSolaris folks to put some work into 
> PostgreSQL as well this year, I'm going to ask them to look over PGACE to see 
> if this implementation is (still) generic enough to support TS as well.  If 
> it is, then it's probably generic enough to be a general building block.

We can extend PGACE framework to mount TrustedSolaris features.
If they need new hooks which is not used in SE-PostgreSQL, it can
remain the default behavior.
The default PGACE behavior gives us no effects in access controls.

A flexible framework is worthwhile for both operating systems.
Please confirm it to the TS folks.

Thanks,
-- 
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai@ak.jp.nec.com>


pgsql-hackers by date:

Previous
From: Tatsuo Ishii
Date:
Subject: Re: Proposal: new large object API
Next
From: KaiGai Kohei
Date:
Subject: Re: [PATCHES] [0/4] Proposal of SE-PostgreSQL patches