Kernel lockdown in 4.17?
Kernel lockdown in 4.17?
Posted Apr 3, 2018 14:45 UTC (Tue) by ju3Ceemi (subscriber, #102464)Parent article: Kernel lockdown in 4.17?
I do not see this as a dump feature
However, I do see this as an ultra-niche feature, something that may, in theory, be useful, but will not be commonly used in the real world
However, I do see this as an ultra-niche feature, something that may, in theory, be useful, but will not be commonly used in the real world
After all, one who wants to "lockdown" a machine with this must own and maintain the whole chain : he must master the bios ""secure boot"" features, for instance. He must compile himself every kernel updates.
If a user can use his own kernel (or any kernel from Debian, redhat or any common distrib), then this user can recompile this kernel without the lockdown code, hence breaking the jail.
I fear that many confusion will rise with such feature.