From 6216087b31d157089087e7d8cbe21835e4c700a9 Mon Sep 17 00:00:00 2001 From: csjp Date: Sun, 18 Sep 2005 03:15:36 +0000 Subject: Introduce a kernel config for the Mandatory Access Control framework. This kernel config briefly describes some of the major MAC policies available on FreeBSD. The hope is that this will raise the awareness about MAC and get more people interested. Discussed with: scottl --- sys/sparc64/conf/MAC | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 sys/sparc64/conf/MAC (limited to 'sys/sparc64/conf') diff --git a/sys/sparc64/conf/MAC b/sys/sparc64/conf/MAC new file mode 100644 index 0000000..56af83d --- /dev/null +++ b/sys/sparc64/conf/MAC @@ -0,0 +1,28 @@ +# MAC -- Generic kernel configuration file for FreeBSD/sparc64 MAC +# +# The Mandatory Access Control, or MAC, framework allows administrators to +# finely control system security by providing for a loadable security pol- +# icy architecture. +# +# For more information see: +# +# http://www.FreeBSD.org/doc/en_US.ISO8859-1/books/handbook/mac.html +# +# $FreeBSD$ + +include GENERIC +ident MAC + +options MAC + +#options MAC_BIBA # BIBA data integrity policy +#options MAC_BSDEXTENDED # File system firewall policy +#options MAC_IFOFF # Network interface silencing policy +#options MAC_LOMAC # Low-watermark data integrity policy +#options MAC_MLS # Multi-level confidentiality policy +#options MAC_NONE # NULL policy +#options MAC_PARTITION # Process partition policy +#options MAC_PORTACL # Network port access control policy +#options MAC_SEEOTHERUIDS # UID visibility policy +#options MAC_STUB # Stub policy +#options MAC_TEST # Testing policy for the MAC framework -- cgit v1.1