Re: [ANNOUNCE][PATCH] New fs to control access to system resources

From: gmack@innerfire.net
Date: Wed Jan 16 2002 - 08:38:30 EST


On Wed, 16 Jan 2002, Andreas Ferber wrote:

> And some wishlist items:
>
> - It would be nice if there were a way to distinguish between TCP and
> UDP ports.
> - IPv6 support would be nice. This raises the question what will
> happen if a process has the privileges to bind a particular port
> with IPv6 but not with IPv4 (IPv6 listeners take IPv4 connections
> also). Is there any value in distinguishing IPv6 and IPv4 at all,
> in particular if IPv6 gets into more widespread use in the future?
> - Restricting access to certain high ports would be valuable. For
> example many SQL server use those ports, and it would be nice if one
> could prevent ordinary user processes from taking over their ports
> in case the SQL daemon gets restarted or the like.
>
> At least accessfs is a nice and expandable idea. Keep up the work :-)
>

What would be nice would be to have a way to restrict access to ports
based on IP ex: user1 gets 10.0.0.1 and user2 gets 10.0.0.2.

        Gerhard

--
Gerhard Mack

gmack@innerfire.net

<>< As a computer I find your faith in technology amusing.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Wed Jan 23 2002 - 21:00:17 EST