Date: Wed, 8 May 2002 17:16:35 +0200 From: Miguel Mendez <flynn@energyhq.homeip.net> To: hackers@freebsd.org Subject: extra sanity check in modules Message-ID: <20020508171635.A50078@energyhq.homeip.net>
next in thread | raw e-mail | index | archive | help
--bp/iNruPH9dso1Pn Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hi, I've been thinking of adding an extra check in kldload. My idea is to have= =20 an md5 sum per module, so for foo.ko we'd have foo.ko.md5. At load time the md5 is checked, if it doesn't test ok the module is not loaded. The md5 files could chflagged as inmutable for extra security. Is it worth having this or just a silly idea? I might start hacking on my DP1 box on this thing later. Cheers, --=20 Miguel Mendez - flynn@energyhq.homeip.net GPG Public Key :: http://energyhq.homeip.net/files/pubkey.txt EnergyHQ :: http://www.energyhq.tk FreeBSD - The power to serve! --bp/iNruPH9dso1Pn Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iD8DBQE82UFTnLctrNyFFPERAtFcAJ9w+GLXGVItLLZEr/UgqlUzjyLa2QCfUPLS I8sHUTm3E8BS4W2Mix4JV+E= =Ynpt -----END PGP SIGNATURE----- --bp/iNruPH9dso1Pn-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020508171635.A50078>