Skip to content

feat: Allow the kernel to verify modules with MOK key#17

Open
kressb-gitlab wants to merge 1 commit intoOpenGamingCollective:mainfrom
kressb-gitlab:ima_config
Open

feat: Allow the kernel to verify modules with MOK key#17
kressb-gitlab wants to merge 1 commit intoOpenGamingCollective:mainfrom
kressb-gitlab:ima_config

Conversation

@kressb-gitlab
Copy link
Copy Markdown

Turning on these Kconfigs allows the kernel to use the MOK key to verify kernel modules. It prevents this in syslog:

Mar 28 13:39:51 bazzite kernel: gcadapter_oc: module verification failed: signature and/or required key missing - tainting kernel

And would also allow refusing unsigned modules completely should that be desired.

@kressb-gitlab
Copy link
Copy Markdown
Author

These Kconfigs were on in the bazzite-kernel for what that is worth.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant