On Thu, Nov 01, 2012 at 10:51:49AM -0400, Vivek Goyal wrote: > And if one wants only /sbin/kexec to call it, then just sign that > one so no other executable will be able to call kexec_load(). Though > I don't think that's the requirement here. Requirement is that only > trusted executables should be able to call kexec_load().
Where "trusted executables" means "signed by a key that's present in the system firmware or in the kernel that's signed with a key that's present in the system firmware", sure. -- Matthew Garrett | [email protected] _______________________________________________ kexec mailing list [email protected] http://lists.infradead.org/mailman/listinfo/kexec
