On Tue, 2011-07-05 at 18:23 +0200, Roberto Sassu wrote:
> Hi all
> 
> this patch set introduces three new modules (masterkey, integrity and
> ecryptfs) and allows to mount the securityfs filesystem from the initial
> ramdisk.
> 
> These patches are based upon the first version sent by Mimi Zohar, which
> can be retrieved at the address:
> 
> http://article.gmane.org/gmane.linux.kernel.initramfs/1910
> 
> Roberto Sassu 

Nice!  Thanks Roberto for updating the modules. They're look really
good.

One really minor issue is that although the user can override the
default masterkey blob filename, using a boot command line option, the
default filename is kernel version specific.  Until the tools are
available to create and seal keys to a set of PCRs, as we discussed,
perhaps there should be an additional filename default, without the
kernel version appended, as well.

thanks,  

Mimi

--
To unsubscribe from this list: send the line "unsubscribe initramfs" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to