[PATCH 07/27] kexec_file: Disable at runtime if securelevel has been set
From: dhowells@redhat.com (David Howells)
Date: 2017-11-02 17:00:14
Also in:
linux-efi, lkml
From: dhowells@redhat.com (David Howells)
Date: 2017-11-02 17:00:14
Also in:
linux-efi, lkml
Mimi Zohar [off-list ref] wrote:
At some point, we'll want to also require the initramfs be signed as well.
That could be tricky. In Fedora, at least, that's assembled on the fly to include just the drivers you need to be able to mount your root fs and find the rest of your modules. (Unless you mean just for the installer) David -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html