Re: [PATCH 00/20] MODSIGN: Use PKCS#7 for module signatures [ver #5]

From: David Woodhouse
Date: Thu May 28 2015 - 11:53:09 EST


On Thu, 2015-05-28 at 16:46 +0100, David Howells wrote:
>
> Additionally, the last four patches are provisionally added to support firmware
> signing, but will need further modification (ie. registration of OIDs) before
> they can be committed, but are included for comment:

I'd quite like to see a way for a given driver to specify the key with
which its firmware needs to be signed. Perhaps an extra argument to the
request_firmware() call giving the X509v3 Subject Key Identifier of the
cert to be trusted?

--
David Woodhouse Open Source Technology Centre
David.Woodhouse@xxxxxxxxx Intel Corporation

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/