#ident "@(#)issues 1.7 08/04/09 SAC" Issues for inception: Validated Execution (PSARC/2008/195) 9 Apr 2008 Submitter: John Zolnowsky Owner: Gary Winiger Intern: Darren Reed gw-0 Case boundaries relative to things like "cat foo | sh" i.e., the relationship with interpreters? djr-0 Further to gw-0, how does this project propose to handle "executable code" that we deliver as text that forms part of libraries for scripting languages, such as perl, ksh, etc. gw-0a Would it help up front to have a walk through of the admin steps for: 1) adding a manifest, 2) adding a cert, 3) changes to an O_VALIDATE file, 4) update to the initial manifest (presuming it includes at least /etc/system which can change kernel memory and is changed by things like bsmconv)? Would Bob Hagmann be proud of this issue? If not, do this as a > 0 issue. ram-1 Leveraging gw-0a, it was unclear to me how one would create, modify and validate an initial manifest? ram-2 Would it be better to move the /etc/signedexec directory to /etc/security/signedexec? gw-1 20Q 3, Why does enabling validated execution by default need "wide adoption of manifests as part of software delivery"? Why isn't this case complete enough to turn validated execution on by default? What's missing? gw-2 20Q 4, Case dependencies Are these all hard dependencies? (Need case number for libxmlsec for commitment) What changes to crypto framework are still needed? (What's the case number of the dependent parts? -- perhaps needed for patch binding Cteam verification) 20Q 11, XML-DSig case? 20Q 13, Are there no imported interfaces? Are there missing exported interfaces? EVALIDATE? 20Q 10, What's interesting to audit here? gw-3 Missing deliverables list: man page for signedexecadm List of files in initial manifest List of manifests delivered by this project and files within them. /etc/signedexec/disable taxonomy? Project Private ;-) gw-4 What is the name space under and how is it managed /etc/signedexec/{manifest,revocation,certlist} How do /etc/certs and /etc/signedexec/certlist differ? How are they administered? gw-5 20Q 7, How does this project meet the SMF Policy? http://opensolaris.org/os/community/arc/policies/SMF-policy/ In particular with relationship to value and action authorizations, and method context? How does this project meet the Solaris Audit Policy? http://opensolaris.org/os/community/arc/policies/audit-policy/ In particular for administrative audit of things like /etc/signedexec/{manifest,revocation,certlist} and signedexecadm? gw-6 Spec 2.1 File Manifests Is there provision for attributes beyond owner, group, POSIX pbits? ACLs, Extended Attributes (attribute files?). What is the hash used for Solaris delivered manifests? gw-7 Spec 2.2 step 2, presumably the manifest entry for the file has its signature validated so the hash for the file can be trusted. If not, why not? A spec update would help make this clearer. Is validation extensible to other attributes? For example extended attributes when they come into critical use. gw-8 Spec 2.3 caching validation in particular invalidated are there parallels to vscan and quarantined? gw-9 Spec 3 how are additions/deletions to certlist managed (including audit)? gw-10 Spec 4 O_VERIFY errno, why not EVALIDATE? djm-0 Possible overlap with PSARC/2007/118 vscan Explain either: a) Why there is zero overlap despite both cases wanting to "validate" files before "use" b) what parts of the vscan case will be used by this case eg the VFS layer hooks, ZFS state etc. White Board: djr-1 What steps are required for ISVs to deliver content covered by this case?