- Subject: Re: [PATCH 21/21] MODSIGN: Apply signature checking to modules on module load [ver #3]
- From: Rusty Russell <rusty@xxxxxxxxxx>
- Date: Fri, 16 Dec 2011 11:11:23 +1030
- Cc: dhowells@xxxxxxxxxx, keyrings@xxxxxxxxxxxxx, linux-crypto@xxxxxxxxxxxxxxx, linux-security-module@xxxxxxxxxxxxxxx, linux-kernel@xxxxxxxxxxxxxxx, dmitry.kasatkin@xxxxxxxxx, zohar@xxxxxxxxxxxxxxxxxx, arjan.van.de.ven@xxxxxxxxx, alan.cox@xxxxxxxxx, Jon Masters <jcm@xxxxxxxxxxxxxx>
- In-reply-to: <24260.1323908071@redhat.com>
- User-agent: Notmuch/0.6.1-1 (http://notmuchmail.org) Emacs/23.3.1 (i686-pc-linux-gnu)
On Thu, 15 Dec 2011 00:14:31 +0000, David Howells <dhowells@xxxxxxxxxx> wrote:
> Rusty Russell <rusty@xxxxxxxxxx> wrote:
>
> > > > We can have false positives, but at worst that make us report EINVAL
> > > > (bad signature) instead of ENOENT (no signature).
> > >
> > > EKEYREJECTED please; that way it's the same as RHEL does now.
> >
> > OK, sure (who knew that was there?).
Oh yes, I read these, but I didn't appreciate that those errnos had
existed for over 6 years.
Cheers,
Rusty.
--
To unsubscribe from this list: send the line "unsubscribe linux-crypto" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
[Kernel]
[Gnu Classpath]
[Gnu Crypto]
[DM Crypt]
[Netfilter]
[Bugtraq]