[PATCH v2 5/5] ima: enable loading of build time generated key on .ima keyring
Mimi Zohar
zohar at linux.ibm.com
Thu Feb 18 23:02:07 UTC 2021
On Thu, 2021-02-18 at 17:00 -0500, Nayna Jain wrote:
> The kernel currently only loads the kernel module signing key onto
> the builtin trusted keyring. To support IMA, load the module signing
> key selectively either onto the builtin or IMA keyring based on MODULE_SIG
> or MODULE_APPRAISE_MODSIG config respectively; and loads the CA kernel
> key onto the builtin trusted keyring.
>
> Signed-off-by: Nayna Jain <nayna at linux.ibm.com>
Always having a CA key would simplify the code. Otherwise for the
patch set,
Reviewed-by: Mimi Zohar <zohar at linux.ibm.com>
More information about the Linux-security-module-archive
mailing list