Showing posts with label selinux. Show all posts
Showing posts with label selinux. Show all posts

Wednesday, January 28, 2009

SELinux KVM QEMU errors

I'm getting close to disabling SELinux under F10. I'm trying to setup a bridged network so that my windows guest can have full access to the network. Windows runs fine in qemu_kvm using the "-net nic -net user" options. My problem is that in bridge mode it uses "-net nic,macaddr=11:22:33:44:55:66 -net tap". When I try to run the virtual machine I get this message "warning: could not configure /dev/net/tun: no virtual network emulation".

Update: I disabled SELinux, but that didn't fix the problem. I got rid of the error by configuring the tap at least somewhat correctly. I still can't get the bridge to work.

Update: My virtual machines now work with bridged networking. The MAC address that I created above doesn't work. You need to make it something else. Use the networking information on this page as a guide to setting it up. I'm using the /etc/qemu-ifup. I use this script to create 3 taps corresponding to three virtual machines so I can run them at the same time. I don't let my scripts for the virtual machine startup run the /etc/qemu-ifup script. If you're running SELinux make sure that you apply the proper labels to the image.

I'm running a machine with 8GBs of RAM on an AMD Phenom II 840 processor. I'm getting good performance with it. I did upgrage the Fedora 10 kvm module to one from Fedora 11 development repos so that it wouldn't have so many problems with audio.

Monday, December 01, 2008

Windows, USB drives, Military

If you hadn't heard, there is a ban on removable re-writable media in effect for the US Military. From what I'm hearing, this could be indefinite. I'm not in any position to know this for a fact, but I've heard that they're looking for a solution to this problem. If it was as easy to fix as not enabling autorun, I'm sure that it would have blown over and personnel would be getting their usb drives back.

The above really illustrates the problem of security in a Windows environment. Targeted exploits are being written that are not caught by virus scanners because they're not common enough in the wild. The virus scanners are doing pattern matching and no one has entered the new pattern. Consumer Reports pointed out just how bad the situation was in 2006.

The interesting thing about this is that this worm/virus probably propagated without the user having admin access. Most people take for granted that when running as a limited user it's harder to infect the system. It looks like this didn't stop this virus, since most of those users won't be running as an admin.

Perhaps it's time that the U.S. Military stopped depending on Windows and decided to use other operating systems. The NSA has provided a very valuable Linux kernel security addon called SELinux. It should be possible to create policies that would prevent this from happening on a linux system.

To begin, the USB drive should not be mounted with execute permission. This will prevent casual program execution. Using SELinux, it should be possible to limit the user to running only applications specified by the admin in the most restricted environment. I don't know how it's done, but it should be possible to prevent all shells and interpreted programs from running code from the USB drive.

I know what you're going to say next. There's a lot of windows applications that are needed. Run them in a virtual machine, but prevent that virtual machine from having access to USB drives. If the user needs data from a drive, the user will have to copy it to an appropriate location. This option will work well in the field. Laptops with virtualization enabled processors will be able to run VMWare or some other vm product reasonably well enough for most applications. Harden the laptop with all of the security that it needs.

In an office environment skip Citrix and provide the users with a virtual machine running on a software like Qumranet's (purchased by RedHat recently) virtual machine products. Watch the video of 1080p HD video being streamed from the virtual machine to a thin client. I hear that Wyse, makers of thin clients, is having a record year with the economy in a slump.