ELF Executable Signing/Verification Comes For Linux

Posted by Michael Larabel on January 16, 2013

Vivek Goyal of Red Hat has published the initial Linux patches for implementing ELF executable signing and verification. This support is similar to Linux kernel module signature verification and is necessitated with the arrival of SecureBoot.

Vivek explains the motivation for this ELF executable signing/verification, "With arrival of secureboot, sys_kexec() is deemed dangerous. One can effectively bypass the secureboot feature and run its own kernel. So Matthew Garret proposed disabling sys_kexec() in secureboot mode. Later in a separate thread it was discussed how to handle the issue of sys_kexec() with secureboot. My takeaway from discussion was that we need to sign /sbin/kexec. Signed executable can get extra capability and we can allow/disallow access to sys_kexec() based on that capability (Thanks to Eric Biederman for the idea). So that's my motivation to make user space signing work so that I can get kdump working with secureboot enabled. There might be other people who might find it useful in general."

These current three patches for implementing the Linux kernel support plus the new "signelf" utility are current described as very crude patches while Vivek Goyal is hoping to solicit feedback on this work. This work currently only supports statically-linked executables with no support for dynamic linking at present and does have some other limitations like not supporting dlopen().

The initial patches for Linux ELF executable signing and verification are currently on the Linux kernel mailing list.

Discuss this article in our forums, IRC channel, or email the author. You can also follow our content via RSS and on social networks like Facebook, Identi.ca, and Twitter (@Phoronix and @MichaelLarabel). Subscribe to Phoronix Premium to view our content without advertisements, view entire articles on a single page, and experience other benefits.
Latest Hardware Reviews
  1. Intel Haswell HD Graphics 4600 vs. AMD Radeon Graphics On Linux
  2. Intel Haswell HD Graphics 4600 Performance On Ubuntu Linux
  3. Intel Core i7 4770K "Haswell" Benchmarks On Ubuntu Linux
  4. The First Experience Of Intel Haswell On Linux
Latest Software Articles
  1. Optimized Binaries Provide Great Benefits For Intel Haswell
  2. 11-Way Linux, BSD Platform Comparison
  3. SNA Acceleration Works Great For Intel Core i7 Haswell
  4. The Linux Evolution For Intel Haswell's Performance
Latest Linux News
  1. Mir's GPLv3 License Is Now Raising Concerns
  2. NVIDIA Driver Soon Likely To Support EGL, Mir
  3. OpenMandriva Goes Into Alpha Form, Russian-Based
  4. NVIDIA Brings Their Linux Driver To ARM
  5. D Language Still Showing Promise, Advancements
  6. Planetary Annihilation Released For Linux Gamers
  7. Gentoo Starts Work On KDE-Wayland Support
  8. NVIDIA To License Its Kepler GPU Technology
  9. KDE's KWin Made Lots Of Progress In 4.11
  10. Ubuntu Announces Carrier Advisory Group
  11. Qt 5.1 Release Candidate 1 Has Arrived
Latest Forum Talk
  1. Mir's GPLv3 License Is Now Raising Concerns
  2. Intel GPU Driver Tries To Rip Out FBDEV Support
  3. D Language Still Showing Promise, Advancements
  4. In-Fighting Continues Over Mir On Non-Unity Ubuntu
  5. VP9 Codec Now Enabled By Default In Chrome
  6. NVIDIA Driver Soon Likely To Support EGL, Mir
  1. Computers
  2. Display Drivers
  3. Graphics Cards
  4. Motherboards
  5. Peripherals
  6. Processors
  7. Software
  8. Operating Systems
  9. All Articles
  1. Linux Benchmarking
  2. OpenBenchmarking.org
  3. Phoronix Test Suite