Describe module signing and relationship to Secure Boot
authorBen Hutchings <ben@decadent.org.uk>
Sat, 10 Aug 2013 15:36:03 +0000 (17:36 +0200)
committerBen Hutchings <ben@decadent.org.uk>
Sat, 10 Aug 2013 17:21:35 +0000 (19:21 +0200)
index.html

index 9d3e258..0713e46 100644 (file)
 </div>
 
 <div class="slide">
+  <h1>Module signing [3.7]</h1>
+  <ul class="incremental">
+    <li>
+      Kernel modules can be signed at build time, and the kernel
+      configured to refuse loading unsigned modules
+    </li>
+    <li>
+      Necessary but not sufficient to implement Secure Boot -
+      we would also need signed kernel images and some other
+      restrictions when booted in this mode
+    </li>
+    <li>
+      Want to make Secure Boot work?  Come to the meeting on Tuesday
+    </li>
+  </ul>
+</div>
+
+<div class="slide">
   <h1>Questions?</h1>
 </div>