Project

General

Profile

Actions

action #109611

closed

[sle][security][sle15sp4] Verify that if we are "secure booted" that kernel lockdown is enabled

Added by msmeissn about 2 years ago. Updated about 2 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
New test
Target version:
-
Start date:
2022-04-07
Due date:
% Done:

100%

Estimated time:
16.00 h
Difficulty:

Description

We have identified cases where we booted in "secure boot" mode, but the kernel was not locked down.

This affected SLES and openSUSE Tumbleweed.

see https://bugzilla.suse.com/show_bug.cgi?id=1198101

$ cat /sys/kernel/security/lockdown
[none] integrity confidentiality

should NOT show [none] here.

Actions

Also available in: Atom PDF