mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "George Spelvin" <linux@horizon.com>
To: linux-kernel@vger.kernel.org
Cc: jwboyer@redhat.com, linux@horizon.com, torvalds@linux-foundation.org
Subject: Re: RFC: sign the modules at install time
Date: 18 Oct 2012 17:31:12 -0400	[thread overview]
Message-ID: <20121018213112.3903.qmail@science.horizon.com> (raw)

The micturator of the Holy Penguin Pee spake:
> (Side note: I hope people realize that the random key is generated
> with a 100-year lifespan. So if you build a kernel today, you do
> potentially have a "year-2112 problem". I'm not horribly worried, but
> I *am* a bit worried about 32-bit time_t overflow and I hope 32-bit
> openssl doesn't do anything odd)

Well, the kernel uses time_t, which should be >= 64 bits on any machine
still operational outside the computer history museum at that time.

But it also allows an expiry time of 0 to indicate "no expiration".  


It's worth noting that in X.509 *keys* don't have expirations; only
*certifications* do.  That is, the signature binding a name to the key.
You can issue any number of certificates, with different expiration dates,
on the same key.

(The only reason that there's this "certificate = key" confusion
is that X.509 doesn't specify a format for a bare key, so the
certificate format is also used as a key container.)

I haven't figured out the kernel key loading procedure, but it's not
clear that it even sets the expiry time.  It does not, for example,
have any equivalent to the X.509 validity start time, so it wasn't
designed with importing certificates in mind.


Even if it is set, you could disable expiration checking on key lookup
and not care about expiration dates.  (Pass no_state_check=true as the
last argument to keyring_search_aux.)

             reply	other threads:[~2012-10-18 21:31 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-10-18 21:31 George Spelvin [this message]
  -- strict thread matches above, loose matches on Subject: below --
2012-10-17 20:36 Linus Torvalds
2012-10-17 22:19 ` David Howells
2012-10-17 22:44   ` Linus Torvalds
2012-10-18  0:54     ` Greg KH
2012-10-18  3:14       ` Linus Torvalds
2012-10-18  3:18         ` Linus Torvalds
2012-10-18  4:34         ` Rusty Russell
2012-10-18 17:16           ` Greg KH
2012-10-18  4:31     ` Rusty Russell
2012-10-18 12:11       ` Josh Boyer
2012-10-18 16:29         ` Linus Torvalds
2012-10-19  0:20           ` Rusty Russell
2012-10-19 11:21           ` David Howells
2012-10-21 23:51             ` Rusty Russell
2012-10-20 16:41           ` Romain Francoise
2012-10-20 16:47             ` Linus Torvalds
2012-10-17 22:26 ` Josh Boyer
2012-10-17 23:07   ` Linus Torvalds
2012-10-17 23:20     ` Josh Boyer
2012-10-17 23:25       ` Linus Torvalds
2012-10-17 23:44         ` Linus Torvalds
2012-10-18  0:06           ` Linus Torvalds
2012-10-17 23:21     ` Linus Torvalds
2012-10-18  0:13       ` Josh Boyer
2012-10-18  4:41       ` Rusty Russell
2012-10-18  1:17 ` Rusty Russell
2012-10-18  3:27   ` Linus Torvalds
2012-10-18  5:34     ` Rusty Russell
2012-10-18 18:46       ` Linus Torvalds
2012-10-18 19:58         ` Josh Boyer
2012-10-19  0:48           ` Rusty Russell
2012-10-19 11:44             ` Josh Boyer
2012-10-19  1:16           ` Rusty Russell
2012-10-19 11:49             ` Josh Boyer
2012-10-19  1:23         ` Rusty Russell
2012-10-19  3:21           ` Stephen Rothwell
2012-10-20  3:53             ` Rusty Russell
2012-10-19 11:25           ` David Howells
2012-10-19 11:30             ` Stephen Rothwell
2012-10-19 11:40             ` Alexander Holler
2012-10-19 19:58           ` Linus Torvalds
2012-10-19 22:04             ` Linus Torvalds
2012-10-22  0:28               ` Rusty Russell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20121018213112.3903.qmail@science.horizon.com \
    --to=linux@horizon.com \
    --cc=jwboyer@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome