Thread (4 messages) 4 messages, 2 authors, 2019-06-17

Re: [RFC PATCH v4 1/1] Add dm verity root hash pkcs7 sig validation.

From: Milan Broz <hidden>
Date: 2019-06-17 13:31:30
Also in: dm-devel, linux-fsdevel, linux-integrity, lkml

On 13/06/2019 03:06, Jaskaran Khurana wrote:
...
Adds DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE: roothash signature *must* be
specified for all dm verity volumes and verification must succeed prior
to creation of device mapper block device.
I had a quick discussion about this and one suggestion was
to add dm-verity kernel module parameter instead of a new config option.

The idea is that if you can control kernel boot commandline, you can add it
there with the same effect (expecting that root device is on dm-verity as well).

Isn't this better option or it is not going to work for you?

Milan
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help