Kernel Source Divergence, Security (was: booting gbde-encrypted filesystem)

Poul-Henning Kamp phk at phk.freebsd.dk
Sun Jul 31 14:07:30 GMT 2005


In message <20050731135919.GA43753 at afields.ca>, Allan Fields writes:

>Yes, this is all very nice, but when is someone actually going to
>commit it? ;)

I'm (as always) short of time, and GBDE is not the top priority
for me for the time being.

So I am more than happy to see people band together and improve
gbde.

The main work necessary is to polish the userland program and that
is relatively trivial programming, so anyone should be able to pick
that up: just go for it.

Giving gbde a taste function so that the root filesystem can be
protected by GBDE, this is also OK by me in principle, but I'd like
to review the patch before it gets committed because there are a
large number of dragons.

In P4:phk_gbde there is the beginning of hw-crypto support through
opencrypto(9), if somebody wants to work on that, get in touch with
me.

-- 
Poul-Henning Kamp       | UNIX since Zilog Zeus 3.20
phk at FreeBSD.ORG         | TCP/IP since RFC 956
FreeBSD committer       | BSD since 4.3-tahoe    
Never attribute to malice what can adequately be explained by incompetence.


More information about the freebsd-security mailing list