https://www.spinics.net/lists/linux-integrity/msg00036.html Missed those because of ML switch.. Why is this needed? This patch in upstream enables EVM when X509 is loaded evm: enable EVM when X509 certificate is loaded https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=26ddabfe96bb7468763c9c92791404d991b16250 -- Thanks, Dmitry