[Bug debuginfod/28204] extend webapi / verification with forthcoming signed-contents archives

mark at klomp dot org sourceware-bugzilla@sourceware.org
Thu Aug 26 20:53:49 GMT 2021


https://sourceware.org/bugzilla/show_bug.cgi?id=28204

Mark Wielaard <mark at klomp dot org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |mark at klomp dot org

--- Comment #2 from Mark Wielaard <mark at klomp dot org> ---
OpenSuse has some documentation IMA here:
https://en.opensuse.org/SDB:Ima_evm#Introduction

Gentoo:
https://wiki.gentoo.org/wiki/Integrity_Measurement_Architecture

How would this be used together with debuginfod? Where/how would the user get
the signatures and how would the client library check those signatures?

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Elfutils-devel mailing list