Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown
From: dhowells@redhat.com (David Howells)
Date: 2017-11-13 21:44:54
Also in:
linux-efi, lkml
From: dhowells@redhat.com (David Howells)
Date: 2017-11-13 21:44:54
Also in:
linux-efi, lkml
Alan Cox [off-list ref] wrote:
So you don't actually need to sign a lot of PC class firmware because it's already signed.
Whilst that may be true, we either have to check signatures on every bit of firmware that the appropriate driver doesn't say is meant to be signed or not bother. David -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html