keylime / keylime/attestation-operator

[Question] Keylime deployment issue

Open
#82 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
11
Forks
10
PR merge metrics
No merged PRs in 30d

Description

Q1

The whitelist collection tool (generate_mb_defstate, creat_runtime_policy) is implemented in Python and requires installation of Python and dependency packages during deployment, which is inconvenient to use. Do you have any suggestions? Using go or rust to re implement these two tools and compile them into independent binary is relatively convenient to use

Q2

Ubuntu system does not enable selinux by default. Using IMA to achieve custom measurement goals on Ubuntu may cause problems. If Ubuntu closes AppArmor and opens selinux, what are the security risks ?

thanks

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by reviewing the deployment requirements for generate_mb_defstate and creat_runtime_policy, then investigate the Ubuntu SELinux/AppArmor and IMA questions; done would require a decided implementation direction and documented security guidance.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, python, rust, ubuntu
Domain
devops, operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.