On Tue, Jun 03, 2014 at 09:06:49AM -0400, Vivek Goyal wrote: > This patch series does not do kernel signature verification yet. I > plan to post another patch series for that. Now bzImage is already > signed with PKCS7 signature I plan to parse and verify those > signatures. Btw, do you have a brief outline on how you are going to do the extension to signature verification? Nothing formal, just enough of an outline that I can see where in the flow it will be plugged in. I was wondering how the whole signature signing and verification will be done, i.e., where do I get the signature, how and who will verify it (I'm guessing the purgatory code), etc, etc. Thanks. -- Regards/Gruss, Boris. Sent from a fat crate under my desk. Formatting is fine. --