Kernel Module Signature Verification Architecture Simulator
CONFIG_MODULE_SIG_FORCE=y
Userspace insmod / finit_module Official Signed Module ELF + PKCS#7 / CMS ~Module signature append~ Unsigned Rootkit (.ko) Raw ELF executable No PKCS#7 trailer Missing cryptographic proof Tampered Module ELF byte modified by attacker PKCS#7 signature present SHA-256 hash mismatch Kernel Module Verification CONFIG_MODULE_SIG_FORCE=y (sig_enforce=1) module_sig_check() Extracts PKCS#7 signature block Computes SHA-256 over ELF binary Verifies against .builtin_trusted_keys Trusted Kernel Keyring Keyring: .builtin_trusted_keys X.509 Root CA / Ephemeral Key Enforce=1: Denies unsigned/bad sig Status: Strict enforcement active Kernel Load Outcome MODULE LOADED Return: 0 (Success) Linked into kernel space Driver init() executed LOAD REJECTED Error: -ENOKEY / -EKEYREJECTED Module memory released Rootkit injection thwarted No Ring 0 execution
Ready. Choose a scenario: Signed Module, Unsigned Module, or Tampered Module.
Step: 0/4