Re: [PATCH V34 09/29] kexec_file: Restrict at runtime if the kernel is locked down
From: James Morris <hidden>
Date: 2019-06-27 18:14:55
Also in:
kexec, linux-security-module, lkml
From: James Morris <hidden>
Date: 2019-06-27 18:14:55
Also in:
kexec, linux-security-module, lkml
On Thu, 27 Jun 2019, Matthew Garrett wrote:
By that metric, on a secure boot system how do we determine that code running in the firmware environment wasn't compromised before it launched the initial signed kernel?
Remote attestation tied to a hardware root of trust, before allowing access to any further resources. -- James Morris [off-list ref]