Skip to content

Rasdaemon does not work when kernel lockdown is enabled #65

Description

@bluikko

Modern distributions enable kernel lockdown by default when UEFI and Secure Boot are enabled.
This breaks rasdaemon because it has no direct access to MSR or debugfs:

kernel: Lockdown: rasdaemon: Direct MSR access is restricted; see man kernel_lockdown.7
kernel: Lockdown: rasdaemon: debugfs is restricted; see man kernel_lockdown.7

I do not know how rasdaemon works but it sounds like perhaps the architecture must change to keep rasdaemon working with kernel lockdown.

The obvious workarounds would be either disable Secure Boot or kernel lockdown - both of which decrease the overall system security and may not be allowed due to company or compliance policies.

As more servers move to modern distributions and Secure Boot this problem will just get more common until it renders rasdaemon obsolete unless it can evolve.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions