> > Enable Kernel Module signatures so any foriegn kernel modules will be
> > refused. (to avoid Kernel Module hacking).
>
> Not practical (unless you break the X server by disallowing /dev/kmem
> and ioports access)
The infrastructure for most of this is present, but it would mean running
with no CAP for raw I/O and that would give several people interesting
restrictions.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/
This archive was generated by hypermail 2b29 : Sun May 07 2000 - 21:00:21 EST