Labeled IPsec Phase 1 Design Review
We are now doing a technical design review of the first phase of Labeled IPsec.
This project adds a minimal Labeled IPsec capability to the kernel
IPsec code, and a related set of changes to the (closed-source)
Solaris IKE to provide minimal support for managing and negotiatiating
sensitivity labels between systems under common management. This
project is intended to lay the groundwork for follow-on work involving
greater flexibility both in label policy and in the types of labels
handled; however, support for other types of labels is out of scope
for this phase.
- Review period: COMPLETED
- Original Review Document, version 0.3
- Revised Review Document, version 0.4
How to participate
- Join the security-discuss mail alias on opensolaris.org.
- Send technical review comments ONLY to that alias. Please do NOT cross post review comments to any other alias; if you believe other communities should be involved in the review, please contact the project lead (Bill Sommerfeld; sommerfeld@sun.com).
on 2009/10/26 13:15