IPE - kódintegritás-ellenőrzőt jelentett be a Microsoft Linuxhoz

Címkék

A Microsoft részéről Deven Bowers küldött egy patchkészletet a Linux kernelhez "Integrity Policy Enforcement LSM (IPE)" címmel:

IPE is a Linux Security Module, which allows for a configurable policy to enforce integrity requirements on the whole system. It attempts to solve the issue of Code Integrity: that any code being executed (or files being read), are identical to the version that was built by a trusted source.

The type of system for which IPE is designed for use is an embedded device with a specific purpose (e.g. network firewall device in a data center), where all software and configuration is built and provisioned by the owner.

Részletek a levélben.

Hozzászólások

Még a végén kiderül, hogy az Azure Linuxon fut. :P