RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-10-19 Thread Krzysztof Struczynski
> From: Krzysztof Struczynski > Sent: Monday, September 14, 2020 2:08 PM > > When Roberto Sassu and Krzysztof Struczynski contacted me about the > > status of Stefan Berger's patch set, based on Yuqiong Sun's work, I was > > under the impression that they

RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-09-14 Thread Krzysztof Struczynski
> From: Mimi Zohar [mailto:zo...@linux.ibm.com] > Sent: Wednesday, September 2, 2020 8:53 PM > > > So I think this can work in the use case where the system owner is > > > responsible for doing the logging and attestation and the tenants just > > > trust the owner without requiring an attestation.

RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-09-14 Thread Krzysztof Struczynski
een > > done before, and as above, users are present too. We could then have > > some consensus on how this should look and later patches might have > > more success at landing. > > > > Would anyone be interested in this and have recommendations on how we > > could

RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-08-21 Thread Krzysztof Struczynski
> From: Christian Brauner [mailto:christian.brau...@ubuntu.com] > On Tue, Aug 18, 2020 at 05:20:07PM +0200, krzysztof.struczyn...@huawei.com > wrote: > > From: Krzysztof Struczynski > > > > IMA has not been designed to work with containers. It handles every > >

RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-08-21 Thread Krzysztof Struczynski
> From: Christian Brauner [mailto:christian.brau...@ubuntu.com] > On Tue, Aug 18, 2020 at 05:20:07PM +0200, krzysztof.struczyn...@huawei.com > wrote: > > From: Krzysztof Struczynski > > > > IMA has not been designed to work with containers. It handles every > >

RE: [RFC PATCH 00/30] ima: Introduce IMA namespace

2020-08-21 Thread Krzysztof Struczynski
> From: James Bottomley [mailto:james.bottom...@hansenpartnership.com] > On Tue, 2020-08-18 at 17:20 +0200, krzysztof.struczyn...@huawei.com > wrote: > > The measurement list remains global, with the assumption that there > > is only one TPM in the system. Each IMA namespace has a unique ID, > > th

RE: [PATCH v2 6/6] ima: Fix return value of ima_write_policy()

2020-04-28 Thread Krzysztof Struczynski
Hi Mimi, > -Original Message- > From: Mimi Zohar [mailto:zo...@linux.ibm.com] > Sent: Tuesday, April 28, 2020 7:47 PM > To: Roberto Sassu ; Krzysztof Struczynski > > Cc: linux-integr...@vger.kernel.org; linux-security-mod...@vger.kernel.org; > linux-kernel@vg