<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://rsbac.gg3.net/lib/styles/feed.css" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://rsbac.gg3.net/feed.php">
        <title>RSBAC: Extending Linux Security Beyond the Limits</title>
        <description></description>
        <link>http://rsbac.gg3.net/</link>
        <image rdf:resource="http://rsbac.gg3.net/lib/images/favicon.ico" />
       <dc:date>2010-03-13T09:23:51+09:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://rsbac.gg3.net/documentation/dev/scm/git?rev=1267803570&amp;do=diff1267803570"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/download?rev=1267718206&amp;do=diff1267718206"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/site/sidebar?rev=1267717878&amp;do=diff1267717878"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/todo?rev=1267533479&amp;do=diff1267533479"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/rc?rev=1267208138&amp;do=diff1267208138"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/documentation/rsbac_handbook/configuration_basics?rev=1267203186&amp;do=diff1267203186"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/rc_old?rev=1267123850&amp;do=diff1267123850"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist?rev=1267123734&amp;do=diff1267123734"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r819?rev=1266688224&amp;do=diff1266688224"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/patches?rev=1266687774&amp;do=diff1266687774"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/home/2009/12/03/123537?rev=1259840597&amp;do=diff1259840597"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/links?rev=1259840111&amp;do=diff1259840111"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/support?rev=1259839985&amp;do=diff1259839985"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/home/2009/11/27/163138?rev=1259336937&amp;do=diff1259336937"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/download/quick?rev=1259324313&amp;do=diff1259324313"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/documentation/rsbac_handbook/appendixes/rsbac_reference/kernel_parameters?rev=1258032176&amp;do=diff1258032176"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/people_using_rsbac?rev=1258023715&amp;do=diff1258023715"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r802?rev=1256772079&amp;do=diff1256772079"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r795?rev=1256772029&amp;do=diff1256772029"/>
                <rdf:li rdf:resource="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r801?rev=1256771873&amp;do=diff1256771873"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://rsbac.gg3.net/lib/images/favicon.ico">
        <title>RSBAC: Extending Linux Security Beyond the Limits</title>
        <link>http://rsbac.gg3.net/</link>
        <url>http://rsbac.gg3.net/lib/images/favicon.ico</url>
    </image>
    <item rdf:about="http://rsbac.gg3.net/documentation/dev/scm/git?rev=1267803570&amp;do=diff1267803570">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-06T00:39:30+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>documentation:dev:scm:git - rewrote!</title>
        <link>http://rsbac.gg3.net/documentation/dev/scm/git?rev=1267803570&amp;do=diff1267803570</link>
        <description>Git

 Git is the version tracking system used by the Linux kernel and increasingly many others. Why?

	*  it is fast
	*  it is compact
	*  it is fully distributed
	*  it is widely supported
	*  it let us import upstream changes directly

 A simple example: The current rsbac-2.6 svn/svk repository is 1.2G, the same git repository is 367M.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/download?rev=1267718206&amp;do=diff1267718206">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-05T00:56:46+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>download - Replace SVN info by GIT</title>
        <link>http://rsbac.gg3.net/download?rev=1267718206&amp;do=diff1267718206</link>
        <description>All the RSBAC code is copyrighted (c) 1997-2009 by Amon Ott &lt;ao@rsbac.org&gt; (except where explicitly stated otherwise in the code), and published under the GNU General Publishing License v2.
Please consult the RSBAC copyright notice for details.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/site/sidebar?rev=1267717878&amp;do=diff1267717878">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-05T00:51:18+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>site:sidebar - removed SVN links</title>
        <link>http://rsbac.gg3.net/site/sidebar?rev=1267717878&amp;do=diff1267717878</link>
        <description>Stable: 1.4.3
  kernel:

	*  2.6.31+

  Full RSBAC kernels 
 Lazy of patching ?
Get the already rsbac-patched kernel. Choose your flavor.

 Classic kernels
 Includes vanilla kernel with the RSBAC patch

	*  2.6.31

 Enhanced kernels
 PaX+RSBAC kernels</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/todo?rev=1267533479&amp;do=diff1267533479">
        <dc:format>text/html</dc:format>
        <dc:date>2010-03-02T21:37:59+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>todo - removed the done tasks, no point</title>
        <link>http://rsbac.gg3.net/todo?rev=1267533479&amp;do=diff1267533479</link>
        <description>RSBAC Progression and Roadmap

 This page reflects our current work queue - if you miss anything here, it will probably not happen. Please discuss any wishes on the  at &lt;rsbac@rsbac.org&gt; or open a bug.

The RSBAC development team.

Planned for the next release 1.5

	*  CAP learning mode for single programs. (possibly 1.4 feature)
		*  Persistent transactions, preserved between reboots.
		*  RC learning mode - per role, with object types already set before learning. Learn only access rights. Use …</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/rc?rev=1267208138&amp;do=diff1267208138">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-27T03:15:38+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:rc - T</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/rc?rev=1267208138&amp;do=diff1267208138</link>
        <description>Back to igraltist's experiences / RC Modules



RC Module

RC Testsetup

Prepare the System to get more verbose description what is missing on RC you should set this debug options. Append in the ``/boot/grub/menu.lst`` for the used rsbac-kernel on line ``kernel``</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/documentation/rsbac_handbook/configuration_basics?rev=1267203186&amp;do=diff1267203186">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-27T01:53:06+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>documentation:rsbac_handbook:configuration_basics - Added a hint where to find &quot;which modules you want&quot;, as users get confused this does not come up first</title>
        <link>http://rsbac.gg3.net/documentation/rsbac_handbook/configuration_basics?rev=1267203186&amp;do=diff1267203186</link>
        <description>Configuration

 You should now have a bootable and usable RSBAC system. You are probably able to boot with the rsbac_softmode boot parameter or rsbac_auth_enable_login (see First Boot)

The next step is to understand what needs to be taken care of, i.e.: to be secured on your system.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/rc_old?rev=1267123850&amp;do=diff1267123850">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-26T03:50:50+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:rc_old</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/rc_old?rev=1267123850&amp;do=diff1267123850</link>
        <description>RC Module

RC Testsetup

Prepare the System to get more verbose description what is missing on RC you should set this debug options. Append in the ``/boot/grub/menu.lst`` for the used rsbac-kernel on line ``kernel``
rsbac_softmode rsbac_nosyslog rsbac_cap_process_hiding rsbac_debug_adf_auth rsbac_debug_adf_rc rsbac_debug_adf_jail rsbac_debug_adf_um rsbac_debug_jail_log_missing_rbsac_debug_cap_log_missing 
This can enter on grubs promt too.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist?rev=1267123734&amp;do=diff1267123734">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-26T03:48:54+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist?rev=1267123734&amp;do=diff1267123734</link>
        <description>This article describes how to run  a VM on a host which has RSBAC + PaX enabled.

My choice is KVM, because it is the easiest to use and already included in the mainline kernel. It performs so well that you can work on the guest system without even noticing that it is a VM.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r819?rev=1266688224&amp;do=diff1266688224">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-21T02:50:24+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:patches:r819</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r819?rev=1266688224&amp;do=diff1266688224</link>
        <description>This patch working on r819.

&lt;http://pax.grsecurity.org/test/pax-linux-2.6.32.8-test17.patch&gt;


diff -r -u rsbac_2.6.32.8-r819_pax/fs/exec.c rsbac_2.6.32.8-r819/fs/exec.c
--- rsbac_2.6.32.8-r819_pax/fs/exec.c	2010-02-20 17:38:53.634180054 +0100
+++ rsbac_2.6.32.8-r819/fs/exec.c	2010-02-20 17:58:20.359693616 +0100
@@ -57,11 +57,24 @@
 #include &lt;linux/fs_struct.h&gt;
 #include &lt;linux/pipe_fs_i.h&gt;
 
+#include &lt;linux/random.h&gt;
+#include &lt;linux/seq_file.h&gt;
+ 
+#ifdef CONFIG_PAX_REFCOUNT
+#include &lt;linux…</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/patches?rev=1266687774&amp;do=diff1266687774">
        <dc:format>text/html</dc:format>
        <dc:date>2010-02-21T02:42:54+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:patches</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/patches?rev=1266687774&amp;do=diff1266687774</link>
        <description>This site contain the patches wich are need if PAX was applied to the rsbac-kernel-source.Iam using the schema r723 as example to associated it with the latest svn update number.
Patches

	*  r795
	*  r802
	*  r819</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/home/2009/12/03/123537?rev=1259840597&amp;do=diff1259840597">
        <dc:format>text/html</dc:format>
        <dc:date>2009-12-03T20:43:17+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>home:2009:12:03:123537 - created</title>
        <link>http://rsbac.gg3.net/home/2009/12/03/123537?rev=1259840597&amp;do=diff1259840597</link>
        <description>OpenSource patches

Thursday, 3/Dec/2009

m-privacy GmbH, the main company funding RSBAC development has opened a new open source website, containing patches and packages for various projects, which you might find interesting.

Specially, you can currently find a few security related patches:</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/links?rev=1259840111&amp;do=diff1259840111">
        <dc:format>text/html</dc:format>
        <dc:date>2009-12-03T20:35:11+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>links - mprivacy oss link</title>
        <link>http://rsbac.gg3.net/links?rev=1259840111&amp;do=diff1259840111</link>
        <description>Linux Distributions with RSBAC

	*  [[Adamantix]] (started as Trusted Debian)
		*  [[&lt;http://www.gentoo.org/proj/en/hardened/rsbac/&gt;|Gentoo Linux]] However various users provide support.
		*  Mandriva
		*  T2
		*  Annvix
		*  ALT Linux Castle
		*  Kaladix Linux
		*  Sniffix, Bencsath Boldizsar made a Knoppix based live CD for RSBAC demonstration. Please read the description first before downloading</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/support?rev=1259839985&amp;do=diff1259839985">
        <dc:format>text/html</dc:format>
        <dc:date>2009-12-03T20:33:05+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>support - Added OSS link</title>
        <link>http://rsbac.gg3.net/support?rev=1259839985&amp;do=diff1259839985</link>
        <description>Array GmbH Professional Support 

Please contact Amon Ott &lt;ao@m-privacy.de&gt; for RSBAC tutorials and workshops, custom setups, security consulting, software development and a handful of other services.  


  
  
  
  
  Services are provided in English or German languages.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/home/2009/11/27/163138?rev=1259336937&amp;do=diff1259336937">
        <dc:format>text/html</dc:format>
        <dc:date>2009-11-28T00:48:57+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>home:2009:11:27:163138 - created</title>
        <link>http://rsbac.gg3.net/home/2009/11/27/163138?rev=1259336937&amp;do=diff1259336937</link>
        <description>RSBAC 1.4.3

Friday, 27/Nov/2009

RSBAC 1.4.3 has been released for kernel 2.6.31.6.

This release focus on adding new learning mode for the RC and CAP modules. We hope you will enjoy it!

Most Important changes since 1.4.2: 

	*  Make RCU rate limit boot and runtime configurable
	*  Move AUTH auth_program_file kernel-only attribute to GEN program_file
	*  Implement CAP learning mode for user and program max_caps
	*  Add global RC learning mode for role rights to types
	*  Optionally put learnin…</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/download/quick?rev=1259324313&amp;do=diff1259324313">
        <dc:format>text/html</dc:format>
        <dc:date>2009-11-27T21:18:33+09:00</dc:date>
        <dc:creator>kang</dc:creator>
        <title>download:quick - 1.4.3</title>
        <link>http://rsbac.gg3.net/download/quick?rev=1259324313&amp;do=diff1259324313</link>
        <description>Quick Install

Install from pre-patched sources:

	*  Unpack pre-patched kernel source tree: tar xvjf linux-X.Y.Z-rsbac-va.b.c-bfN.tar.bz2
	*  cd linux-X.Y.Z-rsbac-va.b.c-bfN
	*  Apply all bugfixes for this RSBAC release with higher number than N (from -bfN) in the same manner, e.g.: cat rsbac-bugfix-vX.Y.Z-M | patch -p1.
	*  make menuconfig
	*  touch Makefile
	*  make dep bzImage modules modules_install
	*  Install the new kernel arch/&lt;arch-name&gt;/boot/bzImage with your favourite boot loader.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/documentation/rsbac_handbook/appendixes/rsbac_reference/kernel_parameters?rev=1258032176&amp;do=diff1258032176">
        <dc:format>text/html</dc:format>
        <dc:date>2009-11-12T22:22:56+09:00</dc:date>
        <dc:creator>ao</dc:creator>
        <title>documentation:rsbac_handbook:appendixes:rsbac_reference:kernel_parameters - Put switch_off last</title>
        <link>http://rsbac.gg3.net/documentation/rsbac_handbook/appendixes/rsbac_reference/kernel_parameters?rev=1258032176&amp;do=diff1258032176</link>
        <description>Kernel Boot Parameters

 The RSBAC kernel accepts the following boot parameters:

General

	*  rsbac_no_defaults: suppress creation of default settings, useful for restore from existing backup. Warning: An unconfigured system will only come up in softmode or maint mode, and softmode will produce loads of logging (see rsbac_nosyslog option...).
	*  rsbac_dac_disable (only, if enabled in kernel config): disable Linux DAC
	*  rsbac_nosyslog: do not log to syslog for this boot time
	*  rsbac_no_init…</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/people_using_rsbac?rev=1258023715&amp;do=diff1258023715">
        <dc:format>text/html</dc:format>
        <dc:date>2009-11-12T20:01:55+09:00</dc:date>
        <dc:creator>ao</dc:creator>
        <title>wiki:people_using_rsbac - Typo</title>
        <link>http://rsbac.gg3.net/wiki/people_using_rsbac?rev=1258023715&amp;do=diff1258023715</link>
        <description>Note: this page is reviewed every now and then. Please respect the entries made by other people. Thank you.



List of people using RSBAC

Companies

	*  m-privacy GmbH, Germany - Supports and help the development RSBAC. Selling RSBAC-enabled products.
	*  Data Contact Kft., Hungary - RSBAC protected firewalls and servers.
	*  BME Crysys Lab, Hungary - Teaching how access control schemes work, laboratory exercise.</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r802?rev=1256772079&amp;do=diff1256772079">
        <dc:format>text/html</dc:format>
        <dc:date>2009-10-29T08:21:19+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:patches:r802 - created</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r802?rev=1256772079&amp;do=diff1256772079</link>
        <description>Back to igraltist's experiences 


diff -u --recursive rsbac_2.6.31.5/fs/exec.c rsbac_2.6.31.5_r802/fs/exec.c
--- rsbac_2.6.31.5/fs/exec.c	2009-10-28 23:55:52.844771089 +0100
+++ rsbac_2.6.31.5_r802/fs/exec.c	2009-10-28 23:43:38.169770699 +0100
@@ -55,12 +55,23 @@
 #include &lt;linux/kmod.h&gt;
 #include &lt;linux/fsnotify.h&gt;
 #include &lt;linux/fs_struct.h&gt;
+#include &lt;linux/random.h&gt;
+#include &lt;linux/seq_file.h&gt;
 
+#ifdef CONFIG_PAX_REFCOUNT
+#include &lt;linux/kallsyms.h&gt;
+#include &lt;linux/kdebug.h&gt;
+#endif
 …</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r795?rev=1256772029&amp;do=diff1256772029">
        <dc:format>text/html</dc:format>
        <dc:date>2009-10-29T08:20:29+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:patches:r795</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r795?rev=1256772029&amp;do=diff1256772029</link>
        <description>Back to igraltist's experiences 


diff -u --recursive rsbac_2.6.31.2_r795/fs/exec.c rsbac_2.6.31.2_pax_r795/fs/exec.c
--- rsbac_2.6.31.2_r795/fs/exec.c	2009-10-11 20:58:27.280751933 +0200
+++ rsbac_2.6.31.2_pax_r795/fs/exec.c	2009-10-11 20:13:22.599876807 +0200
@@ -55,12 +55,23 @@
 #include &lt;linux/kmod.h&gt;
 #include &lt;linux/fsnotify.h&gt;
 #include &lt;linux/fs_struct.h&gt;
+#include &lt;linux/random.h&gt;
+#include &lt;linux/seq_file.h&gt;
 
+#ifdef CONFIG_PAX_REFCOUNT
+#include &lt;linux/kallsyms.h&gt;
+#include &lt;linux/k…</description>
    </item>
    <item rdf:about="http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r801?rev=1256771873&amp;do=diff1256771873">
        <dc:format>text/html</dc:format>
        <dc:date>2009-10-29T08:17:53+09:00</dc:date>
        <dc:creator>Igraltist</dc:creator>
        <title>wiki:experiences:igraltist:patches:r801</title>
        <link>http://rsbac.gg3.net/wiki/experiences/igraltist/patches/r801?rev=1256771873&amp;do=diff1256771873</link>
        <description>diff -u --recursive rsbac_2.6.31.2_r795/fs/exec.c rsbac_2.6.31.2_pax_r795/fs/exec.c
--- rsbac_2.6.31.2_r795/fs/exec.c	2009-10-11 20:58:27.280751933 +0200
+++ rsbac_2.6.31.2_pax_r795/fs/exec.c	2009-10-11 20:13:22.599876807 +0200
@@ -55,12 +55,23 @@
 #include &lt;linux/kmod.h&gt;
 #include &lt;linux/fsnotify.h&gt;
 #include &lt;linux/fs_struct.h&gt;
+#include &lt;linux/random.h&gt;
+#include &lt;linux/seq_file.h&gt;
 
+#ifdef CONFIG_PAX_REFCOUNT
+#include &lt;linux/kallsyms.h&gt;
+#include &lt;linux/kdebug.h&gt;
+#endif
 #include &lt;asm/uac…</description>
    </item>
</rdf:RDF>
