Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-21 Thread Nicolas Williams
On thing that sticks out from the Introduction is this: | However, some applications (e.g. distributed file systems), | most often those not designed for use with Compartmented Mode | Workstations or other Multi-Level Secure (MLS) computers, | multiplex different transactions at differe

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-21 Thread Russ Housley
Nico: So if I understand correctly then this document would have an implementation of, say, NFSv4[0] over TCP[1] send TCP packets for the same TCP connection with different labels, *and* ensure that each packet contains parts of no more than one (exactly one) NFSv4 RPC. I am aware of several m

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-21 Thread Michael StJohns
At 09:44 PM 10/20/2008, Nicolas Williams wrote: >So if I understand correctly then this document would have an >implementation of, say, NFSv4[0] over TCP[1] send TCP packets for the >same TCP connection with different labels, *and* ensure that each packet >contains parts of no more than one (exactl

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-21 Thread Steven M. Bellovin
On Tue, 21 Oct 2008 16:57:12 -0400 Michael StJohns <[EMAIL PROTECTED]> wrote: ... > Classified documents have this thing called paragraph marking. Each > paragraph within a document is marked with the highest level of data > within the paragraph. A page is marked with the highest level of > da

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-22 Thread Bill Sommerfeld
On Mon, 2008-10-20 at 20:44 -0500, Nicolas Williams wrote: > But then: > > |In order to > | maintain data Sensitivity Labeling for such applications, in > | order to be able to implement routing and Mandatory Access > | Control decisions in

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-22 Thread Nicolas Williams
On Tue, Oct 21, 2008 at 04:16:14PM -0400, Russ Housley wrote: > Nico: > > >So if I understand correctly then this document would have an > >implementation of, say, NFSv4[0] over TCP[1] send TCP packets for the > >same TCP connection with different labels, *and* ensure that each packet > >contains

Re: [secdir] Secdir Review of draft-stjohns-sipso-05

2008-10-22 Thread Nicolas Williams
On Tue, Oct 21, 2008 at 04:57:12PM -0400, Michael StJohns wrote: > Classified documents have this thing called paragraph marking. Each > paragraph within a document is marked with the highest level of data > within the paragraph. A page is marked with the highest level of data > in any paragraph