(In reply to Takashi Iwai from comment #8) > The problem isn't too serious on TW because the TW kernel (i.e. the upstream > kernel) still has no strict lockdown. SLE / Leap kernel has a stricter > lockdown, so it can be an actual problem. It might be a problem on TW as > well once when the upstream accepts the more lockdown. Seems we didn't listen closely to Takashi. :-( Can we have "less" lockdown, please? ;-) > IOW, it's not only about CONFIG_MODULE_SIG. Rather the key point is whether > the kernel has a lockdown feature for the unsigned module or not. Hmm. Is this configurable?