Return-path: Received: from e28smtp04.in.ibm.com ([122.248.162.4]:54183 "EHLO e28smtp04.in.ibm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753451AbbHaQpz (ORCPT ); Mon, 31 Aug 2015 12:45:55 -0400 Received: from /spool/local by e28smtp04.in.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Mon, 31 Aug 2015 22:15:52 +0530 Message-ID: <1441039536.2647.73.camel@linux.vnet.ibm.com> (sfid-20150831_184618_938244_C29DF8BD) Subject: Re: Linux Firmware Signing From: Mimi Zohar To: David Woodhouse Cc: "Luis R. Rodriguez" , David Howells , Andy Lutomirski , Kees Cook , "Roberts, William C" , "linux-security-module@vger.kernel.org" , linux-kernel@vger.kernel.org, linux-wireless@vger.kernel.org, "james.l.morris@oracle.com" , "serge@hallyn.com" , Vitaly Kuznetsov , Paul Moore , Eric Paris , selinux@tycho.nsa.gov, Stephen Smalley , "Schaufler, Casey" , "Luis R. Rodriguez" , Dmitry Kasatkin , Greg Kroah-Hartman , Peter Jones , Takashi Iwai , Ming Lei , Joey Lee , =?UTF-8?Q?=22Vojt=C4=9Bch_Pavl=C3=ADk=22?= , Kyle McMartin , Seth Forshee , Matthew Garrett , Johannes Berg , Julia Lawall Date: Mon, 31 Aug 2015 12:45:36 -0400 In-Reply-To: <1441037120.4453.93.camel@infradead.org> References: <476DC76E7D1DF2438D32BFADF679FC5601058E78@ORSMSX103.amr.corp.intel.com> <1440462367.2737.4.camel@linux.vnet.ibm.com> <1440464705.2737.36.camel@linux.vnet.ibm.com> <14540.1440599584@warthog.procyon.org.uk> <31228.1440671938@warthog.procyon.org.uk> <36ddb60c1d22756234392a2d065a02cb.squirrel@twosheds.infradead.org> <20150827212907.GF8051@wotan.suse.de> <1440719673.2118.84.camel@linux.vnet.ibm.com> <20150829021659.GN8051@wotan.suse.de> <1441030735.2647.70.camel@linux.vnet.ibm.com> <1441037120.4453.93.camel@infradead.org> Content-Type: text/plain; charset="UTF-8" Mime-Version: 1.0 Sender: linux-wireless-owner@vger.kernel.org List-ID: On Mon, 2015-08-31 at 17:05 +0100, David Woodhouse wrote: > On Mon, 2015-08-31 at 10:18 -0400, Mimi Zohar wrote: > > I'm not real happy about it, but since we can't break the existing ABI > > of loading data into the kernel via a buffer, a stop gap method of > > signing and verifying a buffer would be needed. > > Actually I think we can. The usermode helper is already being phased > out. Right. The discussion has moved beyond just firmware, but to policies and other things the kernel consumes. Mimi