Re: [PATCH 1/1] selinux: Measure state and hash of policy using IMA

2020-09-28 Thread Lakshmi Ramasubramanian
On 9/28/20 9:29 AM, Stephen Smalley wrote: On Sat, Sep 26, 2020 at 12:40 PM Lakshmi Ramasubramanian wrote: Critical data structures of security modules are currently not measured. Therefore an attestation service, for instance, would not be able to attest whether the security modules are alway

Re: [PATCH 1/1] selinux: Measure state and hash of policy using IMA

2020-09-28 Thread Stephen Smalley
On Sat, Sep 26, 2020 at 12:40 PM Lakshmi Ramasubramanian wrote: > > Critical data structures of security modules are currently not measured. > Therefore an attestation service, for instance, would not be able to > attest whether the security modules are always operating with the policies > and con

[PATCH 1/1] selinux: Measure state and hash of policy using IMA

2020-09-26 Thread Lakshmi Ramasubramanian
Critical data structures of security modules are currently not measured. Therefore an attestation service, for instance, would not be able to attest whether the security modules are always operating with the policies and configurations that the system administrator had setup. The policies and confi