Re: [tboot-devel] [RFC] tboot: kernel signature verification

2019-09-27 Thread Lukasz Hawrylko
Hi Paul Thank you for sharing your work. I will look at this patch and check how it works, idea of measuring kernel signature instead of whole binary is very interesting. I hope that next week I will find some time for that, as you said patch is quite big. Do you plan to add ability to verify pub

Re: [tboot-devel] [RFC] tboot: kernel signature verification

2019-09-27 Thread Paul Moore (pmoore2) via tboot-devel
Hi Lukasz, Thanks for taking a look, I know it is a lot to ask. When looking at the patches I'm mostly concerned about feedback on the general concepts at this stage; the patches are still very much a work in progress. My goal in posting this on-list was to get some feedback now to see if this i