Re: Adding support for SE-Linux security

From: KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
To: Josh Berkus <josh(at)agliodbs(dot)com>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, jd(at)commandprompt(dot)com, David Fetter <david(at)fetter(dot)org>, Itagaki Takahiro <itagaki(dot)takahiro(at)oss(dot)ntt(dot)co(dot)jp>, KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>, pgsql-hackers(at)postgresql(dot)org
Subject: Re: Adding support for SE-Linux security
Date: 2009-12-03 00:27:17
Message-ID: 4B1705E5.9060008@ak.jp.nec.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Josh Berkus wrote:
> Bruce,
>
>> If we decide not to support SE-Linux, it is unlikely we will be adding
>> support for any other external security systems because SE-Linux has the
>> widest adoption.
>>
>> I think the big question is whether we are ready to extend Postgres to
>> support additional security infrastructures.
>
> PostgreSQL is the most security-conscious of the OSS databases, and is
> widely used by certain groups (security software, military, credit card
> processing) precisely because of this reputation. These folks, while
> unlikely to speak up on -hackers, are interested in new/further security
> features; when I was at the Pentagon 2 years ago several people there
> from HS were quite interested in SE-Postgres specifically. Further,
> I've been mentioning SE-Postgres in my "DB security talk" for the last
> 18 months and I *always* get a question about it.
>
> So while there might not be vocal proponents for innovative/hard-core
> security frameworks on this list currently, I think it will gain us some
> new users. Maybe more than we expect.

Good, I also have gotten many voices, questions and requirements from
the viewpoints of enterprise users who make plans to launch their SaaS
system typically.

Thanks,
--
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message KaiGai Kohei 2009-12-03 00:32:05 Re: Adding support for SE-Linux security
Previous Message Alvaro Herrera 2009-12-03 00:10:30 Re: [PATCH] Windows x64