|
|
Log in / Subscribe / Register

IMA/EVM and dm-crypt

IMA/EVM and dm-crypt

Posted Sep 22, 2012 9:55 UTC (Sat) by Max.Hyre (subscriber, #1054)
In reply to: EPERM? ; performance by scripter
Parent article: LSS: Integrity for directories and special files

Please tell me if I'm missing something here, but ISTM the two techniques are not replacements for each other. WRT offline access, dm-crypt is a superset of IMA/EVM.

IMA/EVM is useful if you want to know whether someone has been monkeying with your hard drive while you weren't looking, but does nothing to protect against the NSA reading your data, whereas dm-crypt ensures both no one has modified your data while the system was down, and no one has accessed it, either.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds