When booting the Linux kernel using UEFI SecureBoot, the kernel is put in the lockdown mode to restrict the ability to modify the running kernel image or leaking data from kernel memory. Kernel lockdown mode can also be manually enabled by the user/administrator. Among the limitations imposed in Linux's lockdown mode is no hibernation support. But that soon may be relieved with new patches proposed. Matthew Garrett at NVIDIA sent out a request for comments (RFC) on new patches to allow system hibernation support when running in lockdown mode. Hibernation hasn't been supported in lockdown mode as it's ultimately an attack vector in current form for potentially compromising the system. When hibernating, the contents of the RAM are written to disk and then read back from disk into RAM when resuming the system. The kernel doesn't currently have the ability to ensure that the image written to disk wasn't tampered with at all and thus could be used by bad actors or malware for modifying the kernel image that is then loaded back into RAM or otherwise reading sensitive kernel memory. Matthew Garrett's patches work to address that unencrypted and unauthenticated hibernation handling with TPM-backed security. The patches also involve adding audited TPM sessions in the kernel, generating a TPM signing key for audit sessions, and related infrastructure work. The hibernation image is ultimately securely signed to ensure that it wasn't tampered with during the hibernation process. Those interested in system hibernation support when using the Linux kernel lockdown mode can see the RFC patches for this initial work to address this long-standing obstacle.
Linux Patches Finally Make Hibernation Possible In Secure Boot / Lockdown Mode
Full Article
Original Source
Read the full article at Phoronix →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.