Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933079Ab3IDUOE (ORCPT ); Wed, 4 Sep 2013 16:14:04 -0400 Received: from mail-ob0-f171.google.com ([209.85.214.171]:41507 "EHLO mail-ob0-f171.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753048Ab3IDUOB (ORCPT ); Wed, 4 Sep 2013 16:14:01 -0400 MIME-Version: 1.0 In-Reply-To: <20130904200959.GE8540@anatevka.fc.hp.com> References: <1378252218-18798-1-git-send-email-matthew.garrett@nebula.com> <1378252218-18798-9-git-send-email-matthew.garrett@nebula.com> <20130904200959.GE8540@anatevka.fc.hp.com> Date: Wed, 4 Sep 2013 16:14:00 -0400 X-Google-Sender-Auth: UXhIFKiEwJWm9rZzZWQ316e6lUs Message-ID: Subject: Re: [PATCH V3 08/11] kexec: Disable at runtime if the kernel enforces module loading restrictions From: Josh Boyer To: jerry.hoemann@hp.com Cc: Matthew Garrett , "Linux-Kernel@Vger. Kernel. Org" , "linux-efi@vger.kernel.org" , Kees Cook , "H. Peter Anvin" , kexec , Vivek Goyal Content-Type: text/plain; charset=ISO-8859-1 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1034 Lines: 29 On Wed, Sep 4, 2013 at 4:09 PM, wrote: > On Tue, Sep 03, 2013 at 07:50:15PM -0400, Matthew Garrett wrote: >> kexec permits the loading and execution of arbitrary code in ring 0, which >> is something that module signing enforcement is meant to prevent. It makes >> sense to disable kexec in this situation. >> >> Signed-off-by: Matthew Garrett > > > Matthew, > > Disabling kexec will disable kdump, correct? Yes. > Are there plans to enable kdump on a system where secure > boot is enabled? Vivek Goyal has been working on this. I've not seen the code yet, but I believe it should be posted somewhere relatively soon. We're also planning on talking about it at the Secure Boot microconference at Linux Plumbers in two weeks. josh -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/