forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
David Howells and Eric Biggers proposed PQC ML-DSA pure mode support, but does not support IMA [1].
Summary:
- The ML-DSA implementation supports only "pure" mode, not pre-hash mode.
By not supporting "pre-hash" mode, IMA file hash will be calculated multiple times, once by the kernel for audit and extending the TPM, and again by the ML-DSA crypto. Review the proposed ML-DSA code to see if this is even possible and how hard it would be.
[1] Link: https://lore.kernel.org/linux-integrity/1783975.1769190197@warthog.procyon.org.uk/
Metadata
Metadata
Assignees
Labels
No labels