[PATCH 3/4] ima: use existing read file operation method to calculate file hash

Christoph Hellwig hch at lst.de
Wed Jun 14 07:03:25 UTC 2017


On Tue, Jun 13, 2017 at 11:07:29AM -0400, Mimi Zohar wrote:
> The bigger problem is that files that were previously measured, might
> now not be measured, without any indication in the audit logs or the
> IMA measurement list.

And that's exactly what I've been preaching for a long time - you
need to decide on what your requirements for IMA are and check
for them when enabling it, not just have things sort of work
or not at runtime.
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html



More information about the Linux-security-module-archive mailing list