Kernel signed binaries

  As part of a lockdown system I'm interested in setting up a system
 which will only allow the execution of signed binaries.

  There are a couple of different implementations of this I've seen
 the most promising and up to date appears to be 'digsig'[0].

  Has anybody used anything similar, or have any pointers to 
 other implementations?

[0] = http://disec.sourceforge.net/

