Re: [PATCH 00/12] One more attempt at useful kernel lockdown

From: H. Peter Anvin
Date: Tue Sep 10 2013 - 19:49:25 EST


On 09/10/2013 04:43 PM, Mimi Zohar wrote:
>
> Why invent yet another method of verifying the integrity of a file based
> on a signature? Why not use the existing method for appraising files?
> Just create a new integrity hook at the appropriate place.
>

What would the deliverables be from the hardware vendor and what tools
would you expect them to need on their end?

-hpa


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/