Re: Adding cmldine args measure to ima

2019-03-22 Thread Mimi Zohar
On Fri, 2019-03-22 at 17:27 +, Prakhar Srivastava wrote: > Hi, > > Currently Kexec (kexec_file_load) code path does not measure the cmdline > arguments passed to the next kernel.The boot_aggregate won't change since > the EFI loader hasn't been triggered. Attesting the same in K2 has no impa

Adding cmldine args measure to ima

2019-03-22 Thread Prakhar Srivastava
Hi, Currently Kexec (kexec_file_load) code path does not measure the cmdline arguments passed to the next kernel.The boot_aggregate won't change since the EFI loader hasn't been triggered. Attesting the same in K2 has no impact. Adding the cmdline measurement will add some attestable criteria.