Luis R. Rodriguez <mcg...@suse.com> wrote: > I'll also mention: > > --- > The $DIGEST_ALGORITHM needs to be supported on the running kernel and > > can differ from CONFIG_MODULE_SIG_HASH. > --- > > As I do no think that is quite obvious to a system integrator at first.
Actually, this isn't necessarily so for the firmware. It *is* for the module signing, but you can always load the module to give you the digest algorithm (or public key algorithm) for the firmware. Though you would still have to be careful with firmware loaded during the initramfs phase. David -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/