[Libosinfo] [PATCH 2/8] winxp, installer: Ignore unsigned drivers

Zeeshan Ali (Khattak) zeeshanak at gnome.org
Mon Jan 28 15:05:28 UTC 2013


On Mon, Jan 28, 2013 at 12:19 PM, Christophe Fergeau
<cfergeau at redhat.com> wrote:
> Hey,
>
> On Mon, Jan 28, 2013 at 05:18:41AM +0200, Zeeshan Ali (Khattak) wrote:
>> From: "Zeeshan Ali (Khattak)" <zeeshanak at gnome.org>
>>
>> We are unlikely to find any signed free drivers for windows that are
>> signed. Better just ask windows to ignore.
>
> As this disables some kind of security measures, I'd rather that we don't
> silently disable this, but let the user control this setting and have
> signature checking enabled by default

The problem is that having it configurable would mean that we can't
have a static info on the script about the signature requirement (see
"installer: API to query signed device driver requirement" patch).

I don't really see this a real security feature of windows but more a
control feature of Microsoft as they have made it impossible for free
drivers to be signed. So not very much motivated to do a lot of rework
to accommodate configurability here.

> (the world is not just virtio and qxl
> drivers).

If it was possible to have free (as in Free Software) drivers that
were signed, we wouldn't have issues with virtio and qxl either.

-- 
Regards,

Zeeshan Ali (Khattak)
FSF member#5124




More information about the Libosinfo mailing list