[PATCH v7 3/5] KEYS: Call the IMA hook to measure keys

Lakshmi Ramasubramanian nramas at linux.microsoft.com
Thu Nov 14 18:24:18 UTC 2019


On 11/14/2019 6:54 AM, Mimi Zohar wrote:

> No need to Cc David Howells on the entire patch set.  Just Cc him,
> here, after your tag.
ok

> With this patch, keys are now being measured.  With the boot command
> line, we can verify the measurement entry against /proc/cmdline.  How
> can the key measurement entry be verified?  Please include that
> information, here, in this patch description.

Glad you could verify measurement of keys. Thanks a lot for trying it.

Will add information on testing\validating the feature.

> Also, can the key data, now included in the measurement list, be used
> to verify signatures in the ima-sig or ima-modsig templates?  Is there
> a way of correlating a signature with a key?  Perhaps include a
> kselftest as an example.
> 
> Mimi

I am not familiar with kselftest. Will take a look and see if it'd be 
possible to correlate a signature with a key.

thanks,
  -lakshmi



More information about the Linux-security-module-archive mailing list