Re: [PATCH 2/8] winxp, installer: Ignore unsigned drivers

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Jan 28, 2013 at 12:19 PM, Christophe Fergeau
<cfergeau@xxxxxxxxxx> wrote:
> Hey,
>
> On Mon, Jan 28, 2013 at 05:18:41AM +0200, Zeeshan Ali (Khattak) wrote:
>> From: "Zeeshan Ali (Khattak)" <zeeshanak@xxxxxxxxx>
>>
>> We are unlikely to find any signed free drivers for windows that are
>> signed. Better just ask windows to ignore.
>
> As this disables some kind of security measures, I'd rather that we don't
> silently disable this, but let the user control this setting and have
> signature checking enabled by default

The problem is that having it configurable would mean that we can't
have a static info on the script about the signature requirement (see
"installer: API to query signed device driver requirement" patch).

I don't really see this a real security feature of windows but more a
control feature of Microsoft as they have made it impossible for free
drivers to be signed. So not very much motivated to do a lot of rework
to accommodate configurability here.

> (the world is not just virtio and qxl
> drivers).

If it was possible to have free (as in Free Software) drivers that
were signed, we wouldn't have issues with virtio and qxl either.

-- 
Regards,

Zeeshan Ali (Khattak)
FSF member#5124

_______________________________________________
Libosinfo mailing list
Libosinfo@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libosinfo


[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Fedora Users]     [Fedora Maintainers]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]

  Powered by Linux