Gentoo Archives: gentoo-hardened

From: Maxim Kammerer <mk@×××.su>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] kernel 3.7 -> internal 'udev'; signed lkms; file hash validation
Date: Wed, 19 Dec 2012 21:04:35
Message-Id: CAHsXYDBU5X76saamGoL=DHMarRPN65PpEu0L6ofwqYRQQz8kRQ@mail.gmail.com
In Reply to: Re: [gentoo-hardened] kernel 3.7 -> internal 'udev'; signed lkms; file hash validation by "Tóth Attila"
1 On Wed, Dec 19, 2012 at 10:02 PM, "Tóth Attila" <atoth@××××××××××.hu> wrote:
2 > Integrity Measurement Architecture sounds interesting.
3
4 Last time I have looked into deploying IMA in Liberté Linux, it seemed
5 like a world of pain with outdated kernel patches and a requirement
6 for SELinux if you didn't want to guess the exact form in which file
7 hashes would propagate into IMA backend. You can also forget about it
8 working with anything non-standard like Unionfs. Use Busybox in
9 initramfs? Its mount doesn't support -o iversion. Etc. etc.
10 https://github.com/mkdesu/liberte/commit/73f7bf3
11
12 --
13 Maxim Kammerer
14 Liberté Linux: http://dee.su/liberte

Replies

Subject Author
Re: [gentoo-hardened] kernel 3.7 -> internal 'udev'; signed lkms; file hash validation Sven Vermeulen <sven.vermeulen@××××××.be>