-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ismail Dönmez wrote: | What I meant to ask was what does "per-process securebits" brings as extra.
It allows you to create a legacy free process tree. For example, a chroot, or container (which Serge can obviously explain in more detail), environment in which root has no privilege at all. One in which privilege comes only from filesystem capabilities. | FWIW in Pardus 2008 we'll enable Posix file capabilities by default so people | could "harden" their setups. Cheers Andrew -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQFHpmYd+bHCR3gb8jsRAlDHAJ9RvFRieU2eUPJUHh7K84NMLmytTQCgupfS KxdoXz400AeMWJiaikGH9U8= =yx8I -----END PGP SIGNATURE----- - To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html