[PATCH v1 3/3] KEYS: trusted: Introduce support for NXP CAAM-based trusted keys
Herbert Xu
herbert at gondor.apana.org.au
Thu Apr 1 01:11:32 UTC 2021
On Wed, Mar 31, 2021 at 04:34:29PM -0700, Eric Biggers wrote:
> On Thu, Apr 01, 2021 at 02:31:46AM +0300, Jarkko Sakkinen wrote:
> >
> > It's a bummer but uapi is the god in the end. Since TPM does not do it
> > today, that behaviour must be supported forever. That's why a boot option
> > AND a warning would be the best compromise.
>
> It's not UAPI if there is no way for userspace to tell if it changed.
Exactly. UAPI is only an issue if something *breaks*.
Cheers,
--
Email: Herbert Xu <herbert at gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
More information about the Linux-security-module-archive
mailing list