[PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set

David Howells dhowells at redhat.com
Mon Apr 10 06:19:52 PDT 2017


Mimi Zohar <zohar at linux.vnet.ibm.com> wrote:

> From an IMA perspective, either a file hash or signature are valid,
> but for this usage it must be a signature.

Not necessarily.  If IMA can guarantee that a module is the same based on its
hash rather than on a key, I would've thought that should be fine.

David



More information about the kexec mailing list