Skip to content

Review proposed PQC kernel support #16

@mimizohar

Description

@mimizohar

David Howells and Eric Biggers proposed PQC ML-DSA pure mode support, but does not support IMA [1].

Summary:

  • The ML-DSA implementation supports only "pure" mode, not pre-hash mode.

By not supporting "pre-hash" mode, IMA file hash will be calculated multiple times, once by the kernel for audit and extending the TPM, and again by the ML-DSA crypto. Review the proposed ML-DSA code to see if this is even possible and how hard it would be.

[1] Link: https://lore.kernel.org/linux-integrity/1783975.1769190197@warthog.procyon.org.uk/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions