On Mon, 09 Sep 2013 11:25:38 -0700, David Lang said: > Given that we know that people want signed binaries without blocking kexec, you > should have '1' just enforce module signing and '2' (or higher) implement a full > lockdown including kexec. > Or, eliminate the -1 permanently insecure option and make this a bitmask, if > someone wants to enable every possible lockdown, have them set it to "all 1's", > define the bits only as you need them. This strikes me as much more workable than one big sledgehammer.
Attachment:
pgpdeX7utpgzo.pgp
Description: PGP signature