Re: [PATCH V34 09/29] kexec_file: Restrict at runtime if the kernel is locked down
From: Matthew Garrett <hidden>
Date: 2019-06-27 23:18:00
Also in:
kexec, linux-api, lkml
From: Matthew Garrett <hidden>
Date: 2019-06-27 23:18:00
Also in:
kexec, linux-api, lkml
On Thu, Jun 27, 2019 at 11:14 AM James Morris [off-list ref] wrote:
On Thu, 27 Jun 2019, Matthew Garrett wrote:quoted
By that metric, on a secure boot system how do we determine that code running in the firmware environment wasn't compromised before it launched the initial signed kernel?Remote attestation tied to a hardware root of trust, before allowing access to any further resources.
If you use IMA you can get the same guarantees over kexec.