From mboxrd@z Thu Jan 1 00:00:00 1970 From: James Morris Subject: Re: An actual suggestion (Re: [GIT PULL] Kernel lockdown for secure boot) Date: Thu, 5 Apr 2018 09:25:19 +1000 (AEST) Message-ID: References: <1119.1522858644@warthog.procyon.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Return-path: In-Reply-To: <1119.1522858644@warthog.procyon.org.uk> Sender: linux-kernel-owner@vger.kernel.org To: David Howells Cc: Andy Lutomirski , Greg Kroah-Hartman , "Theodore Y. Ts'o" , Matthew Garrett , Linus Torvalds , Ard Biesheuvel , Alan Cox , Linux Kernel Mailing List , Justin Forbes , linux-man , joeyli , LSM List , Linux API , Kees Cook , linux-efi List-Id: linux-api@vger.kernel.org On Wed, 4 Apr 2018, David Howells wrote: > > 6. There's a way to *decrease* the lockdown level below the configured > > value. (This ability itself may be gated by a config option.) > > Choices include a UEFI protected variable, > > By turning secure boot off, maybe? It's surely reasonable to allow an already secure-booted system to be debugged without needing to be rebooted. - James -- James Morris