cryptsetup.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
* LMS verification support
@ 2022-12-02 15:06 Mike Luken (mluken)
  2022-12-12  8:10 ` Milan Broz
  0 siblings, 1 reply; 2+ messages in thread
From: Mike Luken (mluken) @ 2022-12-02 15:06 UTC (permalink / raw)
  To: cryptsetup

[-- Attachment #1: Type: text/plain, Size: 403 bytes --]

NIST and NSA have both recommended the use of the LMS algorithm for firmware and software signatures and verification.  NSA stated vendors should have this supported in products in 2025.  What are the plans to add LMS support into the kernel for things like secure boot (I guess this is done via the SHIM which I don’t know if this is covered by kernel.org or not) , signed kernel modules and IMA?

[-- Attachment #2: smime.p7s --]
[-- Type: application/pkcs7-signature, Size: 5136 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: LMS verification support
  2022-12-02 15:06 LMS verification support Mike Luken (mluken)
@ 2022-12-12  8:10 ` Milan Broz
  0 siblings, 0 replies; 2+ messages in thread
From: Milan Broz @ 2022-12-12  8:10 UTC (permalink / raw)
  To: Mike Luken (mluken), cryptsetup

On 12/2/22 16:06, Mike Luken (mluken) wrote:
> NIST and NSA have both recommended the use of the LMS algorithm for
> firmware and software signatures and verification.  NSA stated
> vendors should have this supported in products in 2025.  What are the
> plans to add LMS support into the kernel for things like secure boot
> (I guess this is done via the SHIM which I don’t know if this is
> covered by kernel.org or not) , signed kernel modules and IMA?
This is really not a question for this list, I guess you should write
to some kernel list (I guess kernel-integrity, archive here
https://lore.kernel.org/linux-integrity/ )

Milan

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2022-12-12  8:10 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-12-02 15:06 LMS verification support Mike Luken (mluken)
2022-12-12  8:10 ` Milan Broz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).