Re: Proposal for a design for signed kernel/modules/etc

2017-03-29 Thread Conrad Meyer
Hi Eric, Your proposal seems reasonable to me. Others — if you don't have time to read the full email, start reading at "== Proposal==" for a summary of what is actually proposed. You can go back and read the earlier part of the email for some discussion of requirements and other options/context

Re: Proposal for a design for signed kernel/modules/etc

2017-05-21 Thread Conrad Meyer
Hi Eric, On Wed, Mar 29, 2017 at 7:22 PM, Eric McCorkle wrote: >... > == Specifics == > >... > > * A signed ELF will definitely contain a .sign section containing a > single detached signature in PKCS#7 format with DER encoding. I'm concerned about the complexity of parsing PKCS#7 (including ASN