Re: Proposal: Remove MD5 / SHA1 support from veriexec
Matthias Weckbecker <[email protected]> Sat, 26 Aug 2017 21:30:01 +0200
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <20170826213001.396cac91@silentmaxx> |
On Tue, 22 Aug 2017 15:35:57 +0930 Brett Lymn <[email protected]> wrote: [...] > You don't have to up the strict level on veriexec, that way it won't > block execs but, yes, it would not be good if you cannot boot a new > kernel. > One could still boot single user mode where veriexec happens not to be in effect, remount / rw, alter the hashes and be done with it. Not that I'm saying that this is necessarily a good thing, but it's possible. Matthias