Thread (28 messages) 28 messages, 12 authors, 2007-02-16

Re: [PATCH 0/6] MODSIGN: Kernel module signing

From: David Howells <dhowells@redhat.com>
Date: 2007-02-14 19:41:16
Also in: lkml

Linus Torvalds [off-list ref] wrote:
quoted
 (1) A cut-down MPI library derived from GPG with error handling added.
Do we really need to add this?
I presume you mean the MPI library specifically?  If so, then yes.  It's
necessary to do DSA signature verification (or RSA for that matter).
Wouldn't it be much nicer to just teach people to use one of the existing 
signature things that we need for _other_ cases anyway, and already have 
merged?
Existing signature things?  I know not of such beasts, nor can I see them
offhand.
(Of course, it's possible that none of the current crypto supports any 
signature checking at all - I didn't actually look. In which case my 
argument is pointless).
Hashing, yes; encryption, yes; signature checking: no from what I can see.

It's possible that I can share code with eCryptFS, though at first sight that
doesn't seem to overlap with what I want to do.

David
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help