Indeed.
C2 means nothing of the sort.
C2 security implies Discretionary Access Control, and you have ACLs (can't
remember if they are required or whether the Unix user/group/other perms
are good enough).
B1 required Mandatory Access Control where every object has a MAC label.
Even B1 does not involve or require encryption.
None of the Orange Book requirements have anything to say if you can obtain
physical access to the media, since, at that point, "all bets are off" :-)
t
-- Tim Wright, Worldwide Technical Services, | Email: timw@sequent.com Sequent Computer Systems Inc., 15450, | SW Koll Parkway, Beaverton, Oregon 97006 | Phone: +1-503-578-3822 "Nobody ever said I was charming, they said "Rimmer, you're a git!"" RD VI