Re: [PATCH 07/11] kexec: Disable in a secure boot environment
[Posted September 6, 2012 by corbet]
| From: |
| Matthew Garrett <mjg59-AT-srcf.ucam.org> |
| To: |
| "Eric W. Biederman" <ebiederm-AT-xmission.com> |
| Subject: |
| Re: [PATCH 07/11] kexec: Disable in a secure boot environment |
| Date: |
| Wed, 5 Sep 2012 08:03:22 +0100 |
| Message-ID: |
| <20120905070322.GA8014@srcf.ucam.org> |
| Cc: |
| linux-kernel-AT-vger.kernel.org,
linux-security-module-AT-vger.kernel.org, linux-efi-AT-vger.kernel.org |
| Archive-link: |
| Article, Thread
|
On Wed, Sep 05, 2012 at 12:00:31AM -0700, Eric W. Biederman wrote:
> Matthew Garrett <mjg59@srcf.ucam.org> writes:
> > Fine. We'll just carry this one out of tree for now.
>
> It is your tree.
>
> I am disappointed to learn that you aren't enthusiastic about
> implementing verification of signatures for all code that goes into
> ring 0.
I am enthusiastic, but October 26th is a date outside my control and
kexec isn't at the top of the priority list. We ship with the code we
have, not the code we want.
--
Matthew Garrett | mjg59@srcf.ucam.org
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
(
Log in to post comments)