|
|
Subscribe / Log in / New account

Can’t public-key verification be used for third party modules?

Can’t public-key verification be used for third party modules?

Posted Mar 10, 2025 12:18 UTC (Mon) by daroc (editor, #160859)
In reply to: Can’t public-key verification be used for third party modules? by epa
Parent article: Hash-based module integrity checking

Oh, that's a good point. I had assumed that since DKMS modules are built after the kernel on which they depend that this couldn't work, but you're right that you could generate a key, embed the public key in the kernel, and then sign the DKMS build with the private key.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds