A possible step toward integrity measurement for Fedora
A possible step toward integrity measurement for Fedora
Posted Jan 8, 2021 23:23 UTC (Fri) by nivedita76 (subscriber, #121790)In reply to: A possible step toward integrity measurement for Fedora by calumapplepie
Parent article: A possible step toward integrity measurement for Fedora
This isn't about the signatures for the RPMs themselves. It is signatures for each individual file that is part of the package. The kernel's IMA subsystem can then verify those signatures on the running system to ensure that no modified files can be accessed. This is to make sure that the files haven't been tampered with post-installation.
