Luis R. Rodriguez <mcg...@suse.com> wrote:

> I'll also mention:
> 
> ---
> The $DIGEST_ALGORITHM needs to be supported on the running kernel and         
>   
> can differ from CONFIG_MODULE_SIG_HASH.
> ---
> 
> As I do no think that is quite obvious to a system integrator at first.

Actually, this isn't necessarily so for the firmware.

It *is* for the module signing, but you can always load the module to give you
the digest algorithm (or public key algorithm) for the firmware.

Though you would still have to be careful with firmware loaded during the
initramfs phase.

David
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majord...@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Reply via email to