LWN.net Logo

An Overview of the Linux Integrity Subsystem

From:  Mimi Zohar <zohar-AT-linux.vnet.ibm.com>
To:  linux-ima-user-AT-lists.sourceforge.net
Subject:  RFC: An Overview of the Linux Integrity Subsystem
Date:  Fri, 10 Dec 2010 08:37:06 -0500
Message-ID:  <1291988226.3127.15.camel@localhost.localdomain>
Cc:  linux-security-module-AT-vger.kernel.org
Archive-link:  Article, Thread

Following the EVM talk at this year's Linux Security Summit held in
conjunction with LinuxCon, a discussion ensued questioning some of the
integrity design decisions as implemented in the EVM/IMA-appraisal patch
set.  A whitepaper "An Overview of the Linux Integrity Subsystem"
attempts to address these concerns.
(http://downloads.sf.net/project/linux-ima/linux-ima/Integ...)

For anyone interested in the proposed integrity subsystem,
linux-ima.sourceforge.net has been updated with new, hopefully,
simplified installation directions, patches to use the new
Trusted/Encrypted keys, which is now in the security-testing/#next tree,
a few bug fixes, and a sample dracut patch to enable EVM in the
initramfs.  (The patches are against the 2.6.36 stable tree.)

thanks,

Mimi Zohar
David Safford

--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html



(Log in to post comments)

Copyright © 2010, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds