signed executables

Russell Coker via linux-aus <[email protected]>
Newsgroups gmane.linux.australia
Message-ID <6572571.SqbIJfZHni@xev>
https://etbe.coker.com.au/2021/05/10/more-evm/
https://etbe.coker.com.au/2021/04/18/ima-evm-certificates/

I've recently been playing with IMA (Integrity Management Architecture), the 
above blog posts are about my early experiments with it (not yet getting it 
working properly).

When it is working properly it can be configured to only execute or mmap files 
that are RSA signed and also have RSA signatures on SE Linux file context 
labels.  My general idea is to have the signatures made on an internal server 
and then pushed to a production server such that the production server has no 
ability to write a file (not even as root) that the kernel will execute.

Posting to this list because probably lots of people here will be interested, 
and because someone on this list mentioned related things in a conversation.

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/

_______________________________________________
linux-aus mailing list
[email protected]
http://lists.linux.org.au/mailman/listinfo/linux-aus

To unsubscribe from this list, send a blank email to
linux-aus-unsubscribe-cunTk1MwBs8iFSDQTTA3OBCuuivNXqWP@public.gmane.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.