[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20200827.132010.1826967607816087414.davem@davemloft.net>
Date: Thu, 27 Aug 2020 13:20:10 -0700 (PDT)
From: David Miller <davem@...emloft.net>
To: antony.antony@...unet.com
Cc: steffen.klassert@...unet.com, netdev@...r.kernel.org,
herbert@...dor.apana.org.au, smueller@...onox.de,
antony@...nome.org
Subject: Re: [PATCH ipsec-next v3] xfrm: add
/proc/sys/core/net/xfrm_redact_secret
From: Antony Antony <antony.antony@...unet.com>
Date: Thu, 27 Aug 2020 22:15:36 +0200
> If there is a way to set lockdown per net namespace it would be
> better than /proc/sys/core/net/xfrm_redact_secret.
Lockmode is a whole system attribute.
As should any facility that restricts access to keying information
stored inside of the kernel.
Powered by blists - more mailing lists