On Wed, Dec 11, 2013 at 03:26:15PM +0800, Lee, Chun-Yi wrote:
It's base on the kernel patches of Fedora 20.
This patch set add the support to MODSIGN mechanism for revoke kernel
module by hash or public key. As MokListRT, EFI bootloader(e.g. shim)
should maintain the MokListXRT container the format the same with dbx.
The patches will check the hash of kernel module before load it.
Thanks for doing this! A few comments/questions on the patches to
follow.
josh