Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755913Ab3IISxr (ORCPT ); Mon, 9 Sep 2013 14:53:47 -0400 Received: from mail.lang.hm ([64.81.33.126]:54084 "EHLO bifrost.lang.hm" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755136Ab3IISxp (ORCPT ); Mon, 9 Sep 2013 14:53:45 -0400 Date: Mon, 9 Sep 2013 11:53:39 -0700 (PDT) From: David Lang X-X-Sender: dlang@asgard.lang.hm To: Matthew Garrett cc: "Valdis.Kletnieks@vt.edu" , "linux-kernel@vger.kernel.org" , "keescook@chromium.org" , "gregkh@linuxfoundation.org" , "hpa@zytor.com" , "linux-efi@vger.kernel.org" , "jmorris@namei.org" , "linux-security-module@vger.kernel.org" Subject: Re: [PATCH 00/12] One more attempt at useful kernel lockdown In-Reply-To: <1378752158.17982.15.camel@x230.lan> Message-ID: References: <1378741786-18430-1-git-send-email-matthew.garrett@nebula.com> <19562.1378747124@turing-police.cc.vt.edu> <1378751318.17982.10.camel@x230.lan> <1378752158.17982.15.camel@x230.lan> User-Agent: Alpine 2.02 (DEB 1266 2009-07-14) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1105 Lines: 28 On Mon, 9 Sep 2013, Matthew Garrett wrote: > On Mon, 2013-09-09 at 11:40 -0700, David Lang wrote: >> On Mon, 9 Sep 2013, Matthew Garrett wrote: >> >>> On Mon, 2013-09-09 at 11:25 -0700, David Lang wrote: >>> >>>> Given that we know that people want signed binaries without blocking kexec, you >>>> should have '1' just enforce module signing and '2' (or higher) implement a full >>>> lockdown including kexec. >>> >>> There's already a kernel option for that. >> >> So, if there is an existing kernel option for this, why do we need a new one? > > There's an existing kernel option for "I want to enforce module > signatures but I don't care about anything else". There isn't for "I > want to prevent userspace from modifying my running kernel". So is there a way to unify these different things rather than creating yet another different knob? David Lang -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/