Re: [PATCH v1 0/4] ima: require signed user-space initialization

2014-10-10 Thread Dmitry Kasatkin
Hello Andrew, I have just posted updated patchset. Please check patch description where I discuss your questions and related changes. Thanks, Dmitry On 30/07/14 00:37, Dmitry Kasatkin wrote: > On Wed, Jul 23, 2014 at 9:08 PM, Mimi Zohar wrote: >> On Wed, 2014-07-16 at 23:26 +0300, Dmitry Kasatk

Re: [PATCH v1 0/4] ima: require signed user-space initialization

2014-07-29 Thread Dmitry Kasatkin
On Wed, Jul 23, 2014 at 9:08 PM, Mimi Zohar wrote: > On Wed, 2014-07-16 at 23:26 +0300, Dmitry Kasatkin wrote: >> Hello, >> >> >> On Wed, Jul 16, 2014 at 12:33 AM, Andrew Morton >> wrote: >> > On Tue, 15 Jul 2014 15:54:19 +0300 Dmitry Kasatkin >> > wrote: >> > >> >> Currently secure IMA/EVM ini

Re: [PATCH v1 0/4] ima: require signed user-space initialization

2014-07-23 Thread Mimi Zohar
On Wed, 2014-07-16 at 23:26 +0300, Dmitry Kasatkin wrote: > Hello, > > > On Wed, Jul 16, 2014 at 12:33 AM, Andrew Morton > wrote: > > On Tue, 15 Jul 2014 15:54:19 +0300 Dmitry Kasatkin > > wrote: > > > >> Currently secure IMA/EVM initialization has to be done from the initramfs, > >> embedded

Re: [PATCH v1 0/4] ima: require signed user-space initialization

2014-07-16 Thread Dmitry Kasatkin
Hello, On Wed, Jul 16, 2014 at 12:33 AM, Andrew Morton wrote: > On Tue, 15 Jul 2014 15:54:19 +0300 Dmitry Kasatkin > wrote: > >> Currently secure IMA/EVM initialization has to be done from the initramfs, >> embedded in the signed kernel image. Many systems do not want to use >> initramfs or us

Re: [PATCH v1 0/4] ima: require signed user-space initialization

2014-07-15 Thread Andrew Morton
On Tue, 15 Jul 2014 15:54:19 +0300 Dmitry Kasatkin wrote: > Currently secure IMA/EVM initialization has to be done from the initramfs, > embedded in the signed kernel image. Many systems do not want to use > initramfs or usage of embedded initramfs makes it difficult to have > multi-target kerne