RE: [ANNOUNCE] Release Digsig 1.5: kernel module for run-timeauthentication of binaries
- From: "Makan Pourzandi \(QB/EMC\)" <makan.pourzandi@xxxxxxxxxxxx>
- Date: Mon, 24 Apr 2006 12:27:21 -0400
Hi Arjan,
I hope I correctly understood your question, DigSig uses LSM hooks to
check the digital signature before loading it, then as long as your elf
loader uses kernel system calls, it's covered by DigSig.
Regards
Makan
-----Original Message------
From: linux-security-module-owner@xxxxxxxxxxxxxxx
[mailto:linux-security-module-owner@xxxxxxxxxxxxxxx] On
Behalf Of Arjan van de Ven
Sent: April 23, 2006 8:19 AM
To: Makan Pourzandi (QB/EMC)
Cc: linux-kernel@xxxxxxxxxxxxxxx;
linux-security-module@xxxxxxxxxxxxxxx; Serue Hallyen; Axelle
Apvrille; 'disec-devel@xxxxxxxxxxxxxxxxxxxxx'
Subject: Re: [ANNOUNCE] Release Digsig 1.5: kernel module for
run-timeauthentication of binaries
On Fri, 2006-04-21 at 09:56 +0000, Makan Pourzandi wrote:
Hi,1.5 of digsig.
Digsig development team would like to announce the release
Executable and
This kernel module helps system administrators control
Linkable Format (ELF) binary execution and library loading based onfunctionality is
the presence of a valid digital signature. The main
to help system administrators distinguish applicationshe/she trusts
(and therefore signs) from viruses, worms (and othernuisances). It is
based on the Linux Security Module hooks.
does this also prevent people writing their own elf loader in
a bit of perl and just mmap the code ?
-
To unsubscribe from this list: send the line "unsubscribe
linux-security-module" in the body of a message to
majordomo@xxxxxxxxxxxxxxx More majordomo info at
http://vger.kernel.org/majordomo-info.html
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- RE: [ANNOUNCE] Release Digsig 1.5: kernel module for run-timeauthentication of binaries
- From: Arjan van de Ven
- RE: [ANNOUNCE] Release Digsig 1.5: kernel module for run-timeauthentication of binaries
- Prev by Date: Re: [RFC] [PATCH] Make ACPI button driver an input device
- Next by Date: Re: [PATCH 1/1] threads_max: Simple lockout prevention patch
- Previous by thread: [patch 7/13] s390: fix slab debugging.
- Next by thread: RE: [ANNOUNCE] Release Digsig 1.5: kernel module for run-timeauthentication of binaries
- Index(es):