On Wed, Mar 13, 2019 at 6:08 PM Mimi Zohar <zohar@xxxxxxxxxxxxx> wrote: > The IMA hash and EVM hmac combination is fine for offline protection. > It's used for mutable files. For immutable files, there must be > either an IMA or EVM signature. Ok. Is the correct way to handle this to check that the file has a signature, or to extend IMA policy to allow it to provide a requirement that EVM verify a signature rather than an HMAC and have the arch policy set that?