[PATCH v2 0/9] kexec/firmware: support system wide policy requiring signatures

2018-05-17 Thread Mimi Zohar
IMA-appraisal is mostly being used in the embedded or single purpose closed system environments. In these environments, both the Kconfig options and the userspace tools can be modified appropriately to limit syscalls. For stock kernels, userspace applications need to continue to work with older

[PATCH v2 0/9] kexec/firmware: support system wide policy requiring signatures

2018-05-17 Thread Mimi Zohar
IMA-appraisal is mostly being used in the embedded or single purpose closed system environments. In these environments, both the Kconfig options and the userspace tools can be modified appropriately to limit syscalls. For stock kernels, userspace applications need to continue to work with older