Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1628558
| From | Henrique de Moraes Holschuh <hmh@hmh.eng.br> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v4 1/4] KEYS: Insert incompressible bytes to reserve space in bzImage |
| Date | 2017-04-21 21:50 +0200 |
| Message-ID | <tyMJ4-1nm-7@gated-at.bofh.it> (permalink) |
| References | <tysKm-6fJ-9@gated-at.bofh.it> <tysKm-6fJ-17@gated-at.bofh.it> <tytGp-6ND-5@gated-at.bofh.it> <tyusN-7hO-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Thu, 20 Apr 2017, Mehmet Kayaalp wrote: > > On Apr 20, 2017, at 7:13 PM, Henrique de Moraes Holschuh <hmh@hmh.eng.br> wrote: > > On Thu, 20 Apr 2017, Mehmet Kayaalp wrote: > >> Include a random filled binary in vmlinux at the space reserved with > >> CONFIG_SYSTEM_EXTRA_CERTIFICATE. This results in an uncompressed reserved ... > > Alternatively, you could ship a static file with random data that has > > been tested to be uncompressible "enough" for every currently supported > > compression engine, maybe with a bit of a safety margin just in case a > > future compression engine does somewhat better... > > The seed makes it static for a given size, and I tested it to be > incompressible. But I don't know about the safety margin. Even without the If you tested the result to be incompressible enough, it is fine with me. > compression, the reserved size is not accurate. If you reserve 4096 bytes, > the DER encoded certificate inserted is not going to be exactly 4096 either > (for reference, the built-in certificate is 1346 bytes). Compression makes it > a little more inaccurate, but is over-provisioning several hundreds of bytes > a concern when the bzImage is several megabytes? Maybe for embedded, but in that case any overprovisioning would already be too much, and one has to fix the issue in some other way. -- Henrique Holschuh
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v4 0/4] Certificate insertion support for x86 bzImages Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 00:30 +0200
[PATCH v4 1/4] KEYS: Insert incompressible bytes to reserve space in bzImage Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 00:30 +0200
Re: [PATCH v4 1/4] KEYS: Insert incompressible bytes to reserve space in bzImage Henrique de Moraes Holschuh <hmh@hmh.eng.br> - 2017-04-21 01:30 +0200
Re: [PATCH v4 1/4] KEYS: Insert incompressible bytes to reserve space in bzImage Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 02:20 +0200
Re: [PATCH v4 1/4] KEYS: Insert incompressible bytes to reserve space in bzImage Henrique de Moraes Holschuh <hmh@hmh.eng.br> - 2017-04-21 21:50 +0200
[PATCH v4 3/4] KEYS: Support for inserting a certificate into x86 bzImage Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 00:40 +0200
[PATCH v4 4/4] KEYS: Print insert-sys-cert information to stdout instead of stderr Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 00:40 +0200
[PATCH v4 2/4] KEYS: Add ELF class-independent certificate insertion support Mehmet Kayaalp <mkayaalp@linux.vnet.ibm.com> - 2017-04-21 00:40 +0200
csiph-web