From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from mx2.suse.de ([195.135.220.15]) by bombadil.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1jg5Mh-0002GF-Co for kexec@lists.infradead.org; Tue, 02 Jun 2020 11:45:56 +0000 Date: Tue, 2 Jun 2020 13:45:48 +0200 From: Jiri Bohac Subject: Re: [PATCH v2] kexec: Do not verify the signature without the lockdown or mandatory signature Message-ID: <20200602114548.2yevcdfsho4it75u@dwarf.suse.cz> References: <20200602045952.27487-1-lijiang@redhat.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20200602045952.27487-1-lijiang@redhat.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "kexec" Errors-To: kexec-bounces+dwmw2=infradead.org@lists.infradead.org To: Lianbo Jiang Cc: bhe@redhat.com, kexec@lists.infradead.org, jmorris@namei.org, mjg59@google.com, linux-kernel@vger.kernel.org, ebiederm@xmission.com, akpm@linux-foundation.org, dyoung@redhat.com On Tue, Jun 02, 2020 at 12:59:52PM +0800, Lianbo Jiang wrote: > So, here, let's simplify the logic to improve code readability. If the > KEXEC_SIG_FORCE enabled or kexec lockdown enabled, signature verification > is mandated. Otherwise, we lift the bar for any kernel image. > > Signed-off-by: Lianbo Jiang Reviewed-by: Jiri Bohac -- Jiri Bohac SUSE Labs, Prague, Czechia _______________________________________________ kexec mailing list kexec@lists.infradead.org http://lists.infradead.org/mailman/listinfo/kexec