Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document fs-verity integration and plugin usage #1849

Open
davide125 opened this issue Nov 29, 2021 · 2 comments
Open

Document fs-verity integration and plugin usage #1849

davide125 opened this issue Nov 29, 2021 · 2 comments

Comments

@davide125
Copy link
Contributor

Document how to use the fs-verity integration in RPM, specifically the signing flow and the plugin. This is a placeholder issue linked to an upcoming Fedora Change.

@pmatilai
Copy link
Member

Note that the burden of documentation is primarily on those who created the code to begin with.
Of course it was my mistake to merge the code with no accompanying documentation, I guess we didn't have any good place for such docs at that time.

@ebiggers
Copy link

RPM's support for fsverity seems to be based around the idea that fsverity builtin signatures are being used. (RPM calls them simply "fsverity signatures", which is a bit misleading as it's not the only way to have signatures for fsverity files.) The builtin signatures have some problems and are difficult to use; I've been guiding people to use other solutions instead. What ended up being the actual use case here? If there is one, it needs to be clearly documented. I found a Fedora change proposal, but it is missing some essential information, and apparently it was rejected.

Another way to have signatures for fsverity files is through IMA. I'm not sure whether anyone has thought about doing that instead, in the context of RPM.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Backlog
Development

No branches or pull requests

3 participants