Re: [PATCH 00/12] One more attempt at useful kernel lockdown
From: Matthew Garrett
Date: Tue Sep 10 2013 - 14:26:23 EST
On Tue, 2013-09-10 at 14:23 -0300, Henrique de Moraes Holschuh wrote:
> On Tue, 10 Sep 2013, Matthew Garrett wrote:
> > That's why modern systems require signed firmware updates.
>
> Linux doesn't. Is someone working on adding signature support to the
> runtime firmware loader?
It'd be simple to do so, but so far the model appears to be that devices
that expect signed firmware enforce that themselves.
--
Matthew Garrett <matthew.garrett@xxxxxxxxxx>
¢éì®&Þ~º&¶¬+-±éÝ¥w®Ë±Êâmébìdz¹Þ)í
æèw*jg¬±¨¶Ýj/êäz¹Þà2Þ¨èÚ&¢)ß«a¶Úþø®G«éh®æj:+v¨wèÙ>W±êÞiÛaxPjØm¶ÿÃ-»+ùd_