Thread (101 messages) 101 messages, 18 authors, 2018-04-08

Re: [GIT PULL] Kernel lockdown for secure boot

From: Matthew Garrett <hidden>
Date: 2018-04-03 16:30:01
Also in: linux-efi, linux-man, linux-security-module, lkml

Possibly related (same subject, not in this thread)

On Tue, Apr 3, 2018 at 8:11 AM Andy Lutomirski [off-list ref] wrote:
Can you explain that much more clearly?  I'm asking why booting via
UEFI Secure Boot should enable lockdown, and I don't see what this has
to do with kexec.  And "someone blacklist[ing] your key in the
bootloader" sounds like a political issue, not a technical issue.
A kernel that allows users arbitrary access to ring 0 is just an
overfeatured bootloader. Why would you want secure boot in that case?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help