From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751960AbbESUaD (ORCPT ); Tue, 19 May 2015 16:30:03 -0400 Received: from mx1.redhat.com ([209.132.183.28]:38533 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750802AbbESU37 (ORCPT ); Tue, 19 May 2015 16:29:59 -0400 Organization: Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 From: David Howells In-Reply-To: References: <20150519161902.GC23057@wotan.suse.de> <20150518231304.GZ23057@wotan.suse.de> <20150515123610.16723.61913.stgit@warthog.procyon.org.uk> <20150515123513.16723.96340.stgit@warthog.procyon.org.uk> <21177.1431716875@warthog.procyon.org.uk> <8931.1432027524@warthog.procyon.org.uk> <3811.1432054137@warthog.procyon.org.uk> <20150519183508.GL23057@wotan.suse.de> <5419.1432061272@warthog.procyon.org.uk> To: "Luis R. Rodriguez" Cc: dhowells@redhat.com, Rusty Russell , Michal Marek , Matthew Garrett , keyrings@linux-nfs.org, dmitry.kasatkin@gmail.com, "linux-kernel@vger.kernel.org" , Seth Forshee , linux-security-module , David Woodhouse Subject: Re: sign-file and detached PKCS#7 firmware signatures MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-ID: <7181.1432067349.1@warthog.procyon.org.uk> Date: Tue, 19 May 2015 21:29:09 +0100 Message-ID: <7182.1432067349@warthog.procyon.org.uk> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Luis R. Rodriguez wrote: > > Though you would still have to be careful with firmware loaded during the > > initramfs phase. > > Make sense, how about: > > --- > The $DIGEST_ALGORITHM needs to be enabled as built-in (=y) or modular > (=m) in the running kernel and can differ from CONFIG_MODULE_SIG_HASH. > If you are enabling the $DIGEST_ALGORITHM as a module take care to > ensure that this module will also be present on the initramfs used as > some modules within the initramfs may need it if using the Some firmware signatures, not modules. > firmware_class APIs and firmware signing has been enabled. > --- David