Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Mimi Zohar
On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: > On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: > > On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > > > On 8/4/20 11:25 PM, Mimi Zohar wrote: > > > > > > > Hi Lakshmi, > > > > > > > > There's still a number of other patch

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Stephen Smalley
On Wed, Aug 5, 2020 at 9:20 AM Mimi Zohar wrote: > > On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: > > On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: > > > On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > > > > On 8/4/20 11:25 PM, Mimi Zohar wrote: > > > > > > > > > Hi

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Tyler Hicks
On 2020-08-05 10:27:43, Stephen Smalley wrote: > On Wed, Aug 5, 2020 at 9:20 AM Mimi Zohar wrote: > > > > On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: > > > On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: > > > > On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > > > > >

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Stephen Smalley
On 8/4/20 11:25 PM, Mimi Zohar wrote: Hi Lakshmi, There's still a number of other patch sets needing to be reviewed before my getting to this one. The comment below is from a high level. On Tue, 2020-08-04 at 17:43 -0700, Lakshmi Ramasubramanian wrote: Critical data structures of security

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Stephen Smalley
On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: > > On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > > On 8/4/20 11:25 PM, Mimi Zohar wrote: > > > > > Hi Lakshmi, > > > > > > There's still a number of other patch sets needing to be reviewed > > > before my getting to this one. The

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Stephen Smalley
On 8/5/20 11:07 AM, Tyler Hicks wrote: On 2020-08-05 10:27:43, Stephen Smalley wrote: On Wed, Aug 5, 2020 at 9:20 AM Mimi Zohar wrote: On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: On Wed, 2020-08-05 at 08:46 -0400, Stephen

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Mimi Zohar
On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > On 8/4/20 11:25 PM, Mimi Zohar wrote: > > > Hi Lakshmi, > > > > There's still a number of other patch sets needing to be reviewed > > before my getting to this one. The comment below is from a high level. > > > > On Tue, 2020-08-04

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread John Johansen
On 8/5/20 8:43 AM, Stephen Smalley wrote: > On 8/5/20 11:07 AM, Tyler Hicks wrote: > >> On 2020-08-05 10:27:43, Stephen Smalley wrote: >>> On Wed, Aug 5, 2020 at 9:20 AM Mimi Zohar wrote: On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: > On Wed, Aug 5, 2020 at 8:57 AM Mimi

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-05 Thread Mimi Zohar
On Wed, 2020-08-05 at 10:27 -0400, Stephen Smalley wrote: > On Wed, Aug 5, 2020 at 9:20 AM Mimi Zohar wrote: > > On Wed, 2020-08-05 at 09:03 -0400, Stephen Smalley wrote: > > > On Wed, Aug 5, 2020 at 8:57 AM Mimi Zohar wrote: > > > > On Wed, 2020-08-05 at 08:46 -0400, Stephen Smalley wrote: > >

Re: [PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-04 Thread Mimi Zohar
Hi Lakshmi, There's still a number of other patch sets needing to be reviewed before my getting to this one. The comment below is from a high level. On Tue, 2020-08-04 at 17:43 -0700, Lakshmi Ramasubramanian wrote: > Critical data structures of security modules need to be measured to > enable

[PATCH v6 1/4] IMA: Add func to measure LSM state and policy

2020-08-04 Thread Lakshmi Ramasubramanian
Critical data structures of security modules need to be measured to enable an attestation service to verify if the configuration and policies for the security modules have been setup correctly and that they haven't been tampered with at runtime. A new IMA policy is required for handling this