A possible step toward integrity measurement for Fedora
A possible step toward integrity measurement for Fedora
Posted Jan 11, 2021 23:13 UTC (Mon) by ebiggers (subscriber, #130760)In reply to: A possible step toward integrity measurement for Fedora by smurf
Parent article: A possible step toward integrity measurement for Fedora
fs-verity does have optional support for storing signatures with files and having the kernel verify that all fs-verity files are signed by a trusted key. This is much simpler than an IMA policy but also much less flexible; e.g., userspace still needs to check which files have fs-verity enabled. It's really more a proof-of-concept, which happens to be enough for some users who don't want to use IMA.
At some point it's likely that IMA will support fs-verity hashes, so that IMA and fs-verity can be used together. They're not mutually exclusive.
