From: "Luis R. Rodriguez" <mcgrof@suse.com>
To: "Luis R. Rodriguez" <mcgrof@do-not-panic.com>
Cc: ming.lei@canonical.com, rusty@rustcorp.com.au,
torvalds@linux-foundation.org, dhowells@redhat.com,
seth.forshee@canonical.com, linux-kernel@vger.kernel.org,
pebolle@tiscali.nl, linux-wireless@vger.kernel.org,
gregkh@linuxfoundation.org, jlee@suse.com, tiwai@suse.de,
casey@schaufler-ca.com, keescook@chromium.org,
mjg59@srcf.ucam.org, akpm@linux-foundation.org,
Kyle McMartin <kyle@kernel.org>
Subject: Re: [RFC v2 6/6] firmware: add firmware signature checking support
Date: Wed, 13 May 2015 20:46:23 +0200 [thread overview]
Message-ID: <20150513184623.GR23057@wotan.suse.de> (raw)
In-Reply-To: <1431541436-17007-7-git-send-email-mcgrof@do-not-panic.com>
On Wed, May 13, 2015 at 11:23:56AM -0700, Luis R. Rodriguez wrote:
> From: "Luis R. Rodriguez" <mcgrof@suse.com>
>
> As with module signing, we do a very simple search for a
> particular string appended to the firmware. There's both a
> config option and a boot parameter which control whether we
> accept or fail with unsigned firmware and firmware that are
> signed with an unknown key.
>
> If firmware signing is enabled, the kernel will be tainted
> if a firmware is loaded that is unsigned or has a signature
> for which we don't have the key.
Sorry this commit log is obviously still from the v1, the cover
letter addresses the changes best...
Luis
next prev parent reply other threads:[~2015-05-13 18:46 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-05-13 18:23 [RFC v2 0/6] firmware: add PKCS#7 firmware signature support Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 1/6] firmware: generalize reading file contents as a helper Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 2/6] kernel: generalize module signing as system data signing Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 3/6] crypto: qat - address recursive dependency when fw signing is enabled Luis R. Rodriguez
2015-05-14 3:04 ` Herbert Xu
2015-05-14 19:34 ` Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 4/6] scripts/sign-file.c: add support to only create signature file Luis R. Rodriguez
2015-05-14 14:50 ` David Howells
2015-05-14 14:52 ` David Howells
2015-05-14 14:52 ` Luis R. Rodriguez
2015-05-14 15:02 ` David Howells
2015-05-14 15:16 ` Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 5/6] kernel/sysdata_signing: export data_verify_pkcs7() Luis R. Rodriguez
2015-05-13 18:23 ` [RFC v2 6/6] firmware: add firmware signature checking support Luis R. Rodriguez
2015-05-13 18:46 ` Luis R. Rodriguez [this message]
2015-05-14 0:31 ` Julian Calaby
2015-05-14 1:35 ` Luis R. Rodriguez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150513184623.GR23057@wotan.suse.de \
--to=mcgrof@suse.com \
--cc=akpm@linux-foundation.org \
--cc=casey@schaufler-ca.com \
--cc=dhowells@redhat.com \
--cc=gregkh@linuxfoundation.org \
--cc=jlee@suse.com \
--cc=keescook@chromium.org \
--cc=kyle@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=mcgrof@do-not-panic.com \
--cc=ming.lei@canonical.com \
--cc=mjg59@srcf.ucam.org \
--cc=pebolle@tiscali.nl \
--cc=rusty@rustcorp.com.au \
--cc=seth.forshee@canonical.com \
--cc=tiwai@suse.de \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox