Re: hwclock can cause system lockup

2008-10-17 Thread Ian Burrell
Todd Denniston ssa.crane.navy.mil> writes: > > 1) you don't need to call hwclock while NTP is running to keep the hardware > clock synced to system time, the kernel hackers "helpfully" put a sneak > circuit in the ntp implementation in the _kernel_ such that if NTP declares a > good sync with

Re: Whitelisting only digitally signed binaries

2008-09-18 Thread Ian Burrell
McGuffey, David C. saic.com> writes: > > Has any work taken place in the Linux community toward building a > "trusted loader" into Linux. If so, what is the status? If not, why > not? > Check out http://disec.sourceforge.net/. The DigSig kernel module checks digital signatures on ELF binaries