On 03/02/2018, 04:47 PM, Jiri Slaby wrote:
Hi,
On 03/02/2018, 04:38 PM, Marcus Meissner wrote:
The NVIDIA KMP users might not like you for this though... Or we need to think about something for them.
I do not plan to disable loading of unsigned modules (I don't want MODULE_SIG_FORCE). The kernel will just spit on those users, the same it does now for out-of-tree modules.
I.e. the same as on SLE: SLE15:config/x86_64/default:CONFIG_MODULE_SIG=y SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_FORCE is not set SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_ALL is not set SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_SHA1 is not set SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_SHA224 is not set SLE15:config/x86_64/default:CONFIG_MODULE_SIG_SHA256=y SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_SHA384 is not set SLE15:config/x86_64/default:# CONFIG_MODULE_SIG_SHA512 is not set SLE15:config/x86_64/default:CONFIG_MODULE_SIG_HASH="sha256" SLE15:config/x86_64/default:CONFIG_MODULE_SIG_KEY="certs/signing_key.pem"
thanks, -- js suse labs -- To unsubscribe, e-mail: opensuse-kernel+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-kernel+owner@opensuse.org