[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: full drive encryption - check /boot for manipulation



* Michael Heide:

> It simply checks the md5sum of all files in /boot and if there are new
> or vanished files.  It has to be run after every kernel update,
> needless to say.

This doesn't help much against manipulation of /boot.  You need some
kind of trusted boot environment, as provided by one of the original
TPM/TCPA proposals.



Reply to: