Security Topics

Verified Execution (veriexec)

Available

In Review

  1. verified mounts (D2902)

Committed

  1. O_VERIFY flag

Needed

  1. signed manifest support


    We have some X.509-based signed manifest functionality in Junos, but it possibly will not be what the FreeBSD project may want.

  2. veriexec for loader(8) to load kernel, modules, etc.

MAC Framework

Available

  1. allow for MAC modules to effectively do a setuid/setgid operation
    1. this will most likely need to be revisited, as it has been some time since the changes were made in Junos

In Review

Committed

Needed

  1. resolve securelevel and MAC interaction
    1. Currently there are some things that securelevel takes precedence over MAC policies

SteveKiernan/SecurityTopics (last edited 2016-08-10T00:24:03+0000 by SteveKiernan)