On Fri, 2020-08-28 at 08:05 +0200, Petr Vorel wrote: > BTW there are also plans for reboot support [1] [2], that could be used as > workaround for configuration without CONFIG_IMA_READ_POLICY=y and > CONFIG_IMA_WRITE_POLICY=y. The reboot support could also be used for carrying the IMA measurement list across kexec and verifying the TPM PCRs. Mimi