Dailydave mailing list archives

Re: Default Deny on Executables


From: Simon B <simonb () kaizo org>
Date: Wed, 14 Sep 2005 16:23:26 +0100

Quoting miah <miah () chia-pet org>:

DigSig has basically done this.  I've never tried it out, but I'd
be
interested to hear opinions of those that have.

http://disec.sourceforge.net/

#  DigSig. This is a Linux kernel module, which checks RSA digital
#  signatures of ELF binaries and libraries before they are run.
#  Binaries are to be signed with BSign.

The OpenBSD stephanie project too, TPE & Verified Exec.

http://www.innu.org/~brian/Stephanie/

<plea>Abandoned project now, maybe someone here thinks it's cool
enough to pick up </plea>

S.

--
--------------------------------------------------------------------------
Simon B.                                          
http://kaizo.org/simonb
 (finger simonb () kaizo org | gpg --import)            mail
simonb () kaizo org
War is Peace.            Freedom is Slavery.            Bush is
President.
--------------------------------------------------------------------------


Current thread: