[Fedora 09/19] binfmt_elf: Elf executable signature verification

Josh Boyer jwboyer at gmail.com
Thu Sep 5 01:42:42 UTC 2013


On Wed, Sep 4, 2013 at 9:39 PM, Matthew Garrett
<matthew.garrett at nebula.com> wrote:
> There's nothing stopping a signed bootloader from sticking new keys in MOK. We assume that we can trust the signing body.

OK, that's fine.  Maybe throw a comment to that effect in the code.

josh


More information about the kernel mailing list