This Internet-Draft outlines the high-level framework
necessary for the integration of flexible Mandatory Access
Control (MAC) functionality into NFSv4. It allocates
initial identifiers for the existing different label formats.
Working Group Summary
After publishing the requirements for Labeled NFS (as RFC 7204)
and preparing for the upcoming minor version (NFSv4.2) with
Labeled NFS support, there has been a broad consensus to
support a registry of Label Format Specifiers.
The initial assignments captured in this Internet Draft
are built from a long history of operating systems security
structure and use. This document captures the best method
through years of implementation in other file system contexts
along with the implementation in SELinux of an NFS feature set
much like what is captured in the requirements. The content
of this document has received quality feedback and review
throughout its life.
Spencer Shepler (NFSv4 WG co-chair) is the document shepherd
Martin Stiemerling is the Responsible Area Director.