keylime update IMA hash after system update

43 views Asked by At

I want to use keylime to secure a remote computer running in an untrusted environment at the edge. I wondering how to enable system updates using this approach. The hash value of the system is fixed and any changes would change this hash value. Now it might be necessary to run remote updates to roll out new version and update the OS. This would require halting the attestation process and recalculate the IMA hash and reboot the system. This does seem the be challenging. How can this be achieved in an automated way using keylime?

0

There are 0 answers