[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <1452566626.4776.37.camel@linux.vnet.ibm.com>
Date: Mon, 11 Jan 2016 21:43:46 -0500
From: Mimi Zohar <zohar@...ux.vnet.ibm.com>
To: David Howells <dhowells@...hat.com>
Cc: linux-security-module@...r.kernel.org, keyrings@...r.kernel.org,
petkan@...-labs.com, linux-kernel@...r.kernel.org
Subject: Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings
On Tue, 2016-01-12 at 00:38 +0000, David Howells wrote:
> Mimi Zohar <zohar@...ux.vnet.ibm.com> wrote:
>
> > Back in November, Mehmet Kayaalp posted a patch for safely adding
> > additional keys to the system keyring post build and a tool for
> > re-signing the kernel.
> >
> > https://www.mail-archive.com/linux-security-module@vger.kernel.org/msg03679.html
>
> That's irrelevant to this particular discussion.
Not really. The discussion centers around the system keyring and the
origin of the keys on it. These patches safely allow additional keys to
be added post-build to the system keyring.
> And, yes, I should deal with
> his patch.
Thank you.
Mimi
Powered by blists - more mailing lists