Re: Should we automatically generate a module signing key at all?

From: David Howells
Date: Fri May 22 2015 - 18:18:37 EST


Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx> wrote:

> And yes, he would need the ability to insert his own public key in the
> kernel image (he already has the ability to re-sign the modules, we
> have the script for that in the kernel build tree).

With UEFI he could also store his key there. We assume we can trust the keys
there.

David
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/