Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1618548
| From | Dave Young <dyoung@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set |
| Date | 2017-04-07 09:50 +0200 |
| Message-ID | <ttwOC-4ar-27@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <tsZzj-7hF-5@gated-at.bofh.it> <tsZJ0-7kG-7@gated-at.bofh.it> <ttsrD-1tz-1@gated-at.bofh.it> <ttt4m-1IG-3@gated-at.bofh.it> <ttwbT-3XD-13@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 04/07/17 at 08:07am, David Howells wrote: > Dave Young <dyoung@redhat.com> wrote: > > > > > > + /* Don't permit images to be loaded into trusted kernels if we're not > > > > > + * going to verify the signature on them > > > > > + */ > > > > > + if (!IS_ENABLED(CONFIG_KEXEC_VERIFY_SIG) && kernel_is_locked_down()) > > > > > + return -EPERM; > > > > > + > > > > > > > > > > > IMA can be used to verify file signatures too, based on the LSM hooks > > > in kernel_read_file_from_fd(). CONFIG_KEXEC_VERIFY_SIG should not be > > > required. > > > > Mimi, I remember we talked somthing before about the two signature > > verification. One can change IMA policy in initramfs userspace, > > also there are kernel cmdline param to disable IMA, so it can break the > > lockdown? Suppose kexec boot with ima disabled cmdline param and then > > kexec reboot again.. > > I guess I should lock down the parameter to disable IMA too. That is one thing, user can change IMA policy in initramfs userspace, I'm not sure if IMA enforce the signed policy now, if no it will be also a problem. Thanks Dave
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 00/24] Kernel lockdown David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 24/24] Lock down module params that specify hardware parameters (eg. ioport) David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 03/24] efi: Lock down the kernel if booted in secure boot mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-04-06 14:30 +0200
Re: [PATCH 20/24] bpf: Restrict kernel image access functions when the kernel is locked down Ard Biesheuvel <ard.biesheuvel@linaro.org> - 2017-04-06 14:50 +0200
[PATCH 12/24] PCI: Lock down BAR access when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-07 12:30 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-07 15:00 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down Andy Shevchenko <andy.shevchenko@gmail.com> - 2017-04-09 13:20 +0200
Re: [PATCH 15/24] asus-wmi: Restrict debugfs interface when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-10 15:20 +0200
[PATCH 02/24] Add the ability to lock down access to the running kernel image David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 07/24] kexec: Disable at runtime if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
Re: [PATCH 07/24] kexec: Disable at runtime if the kernel is locked down Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
[PATCH 08/24] Copy secure_boot flag in boot params across kexec reboot David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 06/24] Add a sysrq option to exit secure boot mode David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 10/24] hibernate: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:20 +0200
[PATCH 14/24] x86: Restrict MSR access when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
[PATCH 04/24] Enforce module signatures if the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
[PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 01:40 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Oliver Neukum <oneukum@suse.com> - 2017-04-06 08:50 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 11:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down Jiri Kosina <jikos@kernel.org> - 2017-04-06 22:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down poma <pomidorabelisima@gmail.com> - 2017-04-08 05:30 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down David Howells <dhowells@redhat.com> - 2017-04-06 09:00 +0200
Re: [PATCH 11/24] uswsusp: Disable when the kernel is locked down "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-06 22:20 +0200
[PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-05 22:30 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 05:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 05:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 08:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 10:30 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Dave Young <dyoung@redhat.com> - 2017-04-07 10:10 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 09:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 09:50 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-07 11:20 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-07 14:40 +0200
Re: [PATCH 09/24] kexec_file: Disable at runtime if securelevel has been set David Howells <dhowells@redhat.com> - 2017-04-10 15:30 +0200
Re: [PATCH 00/24] Kernel lockdown "Austin S. Hemmelgarn" <ahferroin7@gmail.com> - 2017-04-07 18:10 +0200
Re: [PATCH 00/24] Kernel lockdown Justin Forbes <jmforbes@linuxtx.org> - 2017-04-07 18:40 +0200
csiph-web