[$] Supporting PGP keys and signatures in the kernel

Post Syndicated from original https://lwn.net/Articles/882426/rss

A few weeks back, we looked at a proposal
to add an integrity-management feature to Fedora. One of the selling
points was that the integrity checking could be done using the PGP
signatures that are already embedded into the RPM package files that Fedora
uses. But the kernel needs to be able to verify PGP signatures in order
for the Fedora feature to work. That addition to the kernel has been proposed, but
some in the kernel-development community seem less than completely
enthusiastic about bringing PGP support into the kernel itself.