On Mon, Jul 27, 2015 at 3:43 PM, David Howells <[email protected]> wrote: > Andy Lutomirski <[email protected]> wrote: > >> With all this stuff applied, will the kernel accept PKCS#7 signatures that >> *don't* have authenticated attributes or that are otherwise cryptographically >> insecure in that they fail to provide the property that an attacker can't >> manipulate a valid signature on one message to look like a valid signature on >> a different message? > > Hmmm... That's easy enough to fix (see below). However, will that cause > kexec problems, I wonder? Does mscode require authattrs? >
Seems sensible. How would it cause kexec problems? I can only see it being a problem if Authenticode can't handle authattrs, right? There shouldn't be any legacy PKCS7 kexec images whatsoever, because no existing kernel will boot them or generate them. --Andy -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

