Kdump with signed images
mjg at redhat.com
Thu Nov 1 10:57:31 EDT 2012
On Thu, Nov 01, 2012 at 10:51:49AM -0400, Vivek Goyal wrote:
> And if one wants only /sbin/kexec to call it, then just sign that
> one so no other executable will be able to call kexec_load(). Though
> I don't think that's the requirement here. Requirement is that only
> trusted executables should be able to call kexec_load().
Where "trusted executables" means "signed by a key that's present in the
system firmware or in the kernel that's signed with a key that's present
in the system firmware", sure.
Matthew Garrett | mjg59 at srcf.ucam.org
More information about the kexec