public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider
@ 2007-06-18 20:40 Mimi Zohar
  2007-06-28 14:23 ` Pavel Machek
  0 siblings, 1 reply; 2+ messages in thread
From: Mimi Zohar @ 2007-06-18 20:40 UTC (permalink / raw)
  To: linux-kernel; +Cc: safford, serue, zohar

This is a request for comments for a subset of the original integrity
patches. By submitting this subset of the original patches, we hope to
simplify its review and ultimately ease its inclusion into the kernel.
For this reason, neither EVM nor SLIM are included in this patchset.
This patchset contains: Linux Integrity Module(LIM), Integrity
Measurement Architecture (IMA), and patches to the TPM driver. The LIM
patch defines 3 integrity API calls, 7 integrity hooks, placement of 
the hooks, and a dummy integrity service provider. There are very minor
changes from the previous release.  The IMA patch is now an independent
integrity service provider, which provides support for a subset of the
integrity API calls.

IBAC, a sample LSM module, which helps clarify the interaction between
LSM and LIM modules, will be posted separately to the LSM mailing list.
In addition, we are working on an SELinux integrity patch to take 
advantage of the integrity services, in a similar way to the IBAC
example.


Patch 1/3 integrity: Linux Integrity Module (LIM)
Patch 2/3 integrity: IMA as a stand alone integrity service provider
Patch 3/3 integrity: TPM internal kernel interface

Mimi Zohar
Dave Safford



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider
  2007-06-18 20:40 [RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider Mimi Zohar
@ 2007-06-28 14:23 ` Pavel Machek
  0 siblings, 0 replies; 2+ messages in thread
From: Pavel Machek @ 2007-06-28 14:23 UTC (permalink / raw)
  To: Mimi Zohar; +Cc: linux-kernel, safford, serue, zohar

Hi!

> This is a request for comments for a subset of the original integrity
> patches. By submitting this subset of the original patches, we hope to
> simplify its review and ultimately ease its inclusion into the kernel.

We still don't know what these are good for...

...preventing user from taking out hdd and modifying binaries?

...if user can do that, why is he unable to remove the lim.ko, too?

TPM?

Why this won't be abused to prevent me from playing with hardware I
own?

							Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2007-06-28 14:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-18 20:40 [RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider Mimi Zohar
2007-06-28 14:23 ` Pavel Machek

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox