Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1761615Ab3DKSm7 (ORCPT ); Thu, 11 Apr 2013 14:42:59 -0400 Received: from mail-wg0-f50.google.com ([74.125.82.50]:43719 "EHLO mail-wg0-f50.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756630Ab3DKSm4 (ORCPT ); Thu, 11 Apr 2013 14:42:56 -0400 MIME-Version: 1.0 In-Reply-To: <20130411145550.GD21260@redhat.com> References: <20130405135000.GB6299@redhat.com> <1365450229.3847.56.camel@falcor1.watson.ibm.com> <20130408200904.GI28292@redhat.com> <20130409143852.GH6320@redhat.com> <1365563230.3074.107.camel@falcor1.watson.ibm.com> <20130410194209.GF6602@redhat.com> <1365627922.2452.32.camel@falcor1.watson.ibm.com> <20130411145550.GD21260@redhat.com> Date: Thu, 11 Apr 2013 21:42:54 +0300 Message-ID: Subject: Re: [RFC 2/2] initramfs with digital signature protection From: Dmitry Kasatkin To: Vivek Goyal Cc: Mimi Zohar , Josh Boyer , Matthew Garrett , linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1239 Lines: 35 On Thu, Apr 11, 2013 at 5:55 PM, Vivek Goyal wrote: > On Thu, Apr 11, 2013 at 11:06:55AM +0300, Dmitry Kasatkin wrote: >> Hello, >> >> I respond to the original question of this thread. >> signed initramfs allows not only to add keys to the keyrings but perform >> other initialization, >> which requires user-space. >> Keys can be embedded into the kernel. This is fine. > > What other initialization user space need to do where we can't trust > root (even in secureboot mode). > > IOW, if keys can be embedded in kernel (or read from UEFI db and MOK db), > what other operation requires initramfs to be signed. It could very well > be unsigned initramfs like today. > It looks like you do not hear me. I said that any user space initialization can be done from signed user space. For example IMA policy can be initialized. I see that you see your particular case and in that case you do not require that. That is fine. That is your case.... - Dmitry > Thanks > Vivek -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/