Snawoot / linux-secureboot-kit

Tool for complete hardening of Linux boot chain with UEFI Secure Boot
MIT License
72 stars 11 forks source link

dkms module signature support #4

Closed Snawoot closed 5 years ago

Snawoot commented 5 years ago

Covers #3

Implements DKMS POST_BUILD hook, which chains after original POST_BUILD hook and signs module with db.key.

On ubuntu overrides signing facility, which added by Ubuntu to DKMS to trigger update-secureboot-policy and sign modules with MOK keys. We don't need to enroll MOK keys since we are OK with db.key.