[go: up one dir, main page]

|
|
Log in / Subscribe / Register

[RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider

From:  Mimi Zohar <zohar@linux.vnet.ibm.com>
To:  linux-kernel@vger.kernel.org
Subject:  [RFC][Patch 0/3] integrity: Linux Integrity Module(LIM) and provider
Date:  Mon, 18 Jun 2007 16:40:30 -0400
Cc:  safford@watson.ibm.com, serue@linux.vnet.ibm.com, zohar@us.ibm.com

This is a request for comments for a subset of the original integrity
patches. By submitting this subset of the original patches, we hope to
simplify its review and ultimately ease its inclusion into the kernel.
For this reason, neither EVM nor SLIM are included in this patchset.
This patchset contains: Linux Integrity Module(LIM), Integrity
Measurement Architecture (IMA), and patches to the TPM driver. The LIM
patch defines 3 integrity API calls, 7 integrity hooks, placement of 
the hooks, and a dummy integrity service provider. There are very minor
changes from the previous release.  The IMA patch is now an independent
integrity service provider, which provides support for a subset of the
integrity API calls.

IBAC, a sample LSM module, which helps clarify the interaction between
LSM and LIM modules, will be posted separately to the LSM mailing list.
In addition, we are working on an SELinux integrity patch to take 
advantage of the integrity services, in a similar way to the IBAC
example.


Patch 1/3 integrity: Linux Integrity Module (LIM)
Patch 2/3 integrity: IMA as a stand alone integrity service provider
Patch 3/3 integrity: TPM internal kernel interface

Mimi Zohar
Dave Safford




Copyright © 2007, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds