Thread (3 messages) 3 messages, 3 authors, 2007-02-16

Re: [PATCH 0/6] MODSIGN: Kernel module signing

From: <hidden>
Date: 2007-02-15 20:35:07
Also in: lkml

On Wed, 14 Feb 2007 22:14:53 PST, Andreas Gruenbacher said:
I agree, that's really what should happen. We solve this by marking modules as
supported, partner supported, or unsupported, but in an "insecure" way, so
partners and users could try to fake the support status of a module and/or
remove status flags from Oopses, and cryptography wouldn't save us.
Where cryptography *can* save you is that a partner or user can't fake a
'Suse Supported' signature without access to the Suse private key.

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help