Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Kernel lockdown mode not enabled? #33320

Closed
ghost opened this issue Oct 4, 2021 · 4 comments
Closed

Kernel lockdown mode not enabled? #33320

ghost opened this issue Oct 4, 2021 · 4 comments
Labels

Comments

@ghost
Copy link

ghost commented Oct 4, 2021

Hello,

I've just noticed that kernel lockdown mode (integrity/confidentiality) that was introduced in Linux 5.4 is not enabled in Void

/bin/sh: cat: /sys/kernel/security/lockdown: No such file or directory

Is there any reason for that?

@Meister1593
Copy link

Curious too

@Duncaen
Copy link
Member

Duncaen commented Oct 8, 2021

Enabling it without the bits to make use of it doesn't make much sense, but I doubt there is anything stopping us from enabling it if someone comes up with a setup.

Not even sure if we can make a generic setup for that, what or who would sign the modules? Should this be a key owned by void, what about the initramfs then?

@ericonr
Copy link
Member

ericonr commented Oct 8, 2021

We have discussed signing here previously #27736

I feel like this would probably break my setup, since I boot with secure boot enabled.

@github-actions
Copy link

github-actions bot commented Jun 6, 2022

Issues become stale 90 days after last activity and are closed 14 days after that. If this issue is still relevant bump it or assign it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants