[Ksummit-discuss] [TECH TOPIC] Signature management - keys, modules, firmware, was: Last minute nominations: mcgrof and toshi

David Woodhouse dwmw2 at infradead.org
Fri Aug 12 12:39:11 UTC 2016


On Fri, 2016-08-12 at 18:08 +0530, Vinod Koul wrote:
> Any solution needs to comprehend that additional signing might be
> present.

I would go further than that: Any solution needs to be able to *use*
existing signatures. I don't like your use of the term "additional
signing".

It's for that reason that I think we actually want to (hold our noses
and) support Authenticode signatures too. Because some firmware images
we want to use are available with original signatures in that form.

-- 
David Woodhouse                            Open Source Technology Centre
David.Woodhouse at intel.com                              Intel Corporation

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5760 bytes
Desc: not available
URL: <http://lists.linuxfoundation.org/pipermail/ksummit-discuss/attachments/20160812/53097664/attachment.bin>


More information about the Ksummit-discuss mailing list