A good idea would be to allow loading/unloading of modules only for root...
oh way it is already the case...
> Since the only cryptographic process here would be signing, I don't think
> this would impact kernel distribution.
It wont help against root intruders. Unless the trust model inside the linux
kernels gets an additional "ring" you cant be safe about root users
compromising your system. Capabilities of course do help here.
Greetings
Bernd
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/