[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [saag] Common labeled security (comment on CALIPSO, labeled NFSv4)



Nico:

On Mon, Apr 06, 2009 at 07:03:32AM -0400, Santosh Chokhani wrote:
> I view SPIF as performing the following functions: converting machine to
> human representation and vice versa; establishing equivalency between
> two labeling policies, and defining which labels with the lattice are
> valid and which are invalid.

If I understand Russ' comment correctly the difficulty with SPIF lies in
the label equivalency concept.  I think there's a better solution for
dealing with the idea that parts of a policy are classified differently
than others.

No.  They are two separate concerns.

Mapping labels between two different policies. Hopefully this can be avoided altogether in the NFS context.

Some label values are not releasable to clients that do not have access to data associated with that label. This one is a real-world problem, and it leads to different clients having different subsets of the SPIF if this community that is being supported has this requirement in their policy.

Russ

Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.