[RFC PATCH v14 17/19] scripts: add boot policy generation program

Randy Dunlap rdunlap at infradead.org
Thu Mar 7 00:05:23 UTC 2024



On 3/6/24 15:34, Fan Wu wrote:
>  if SECURITY_IPE
> +config IPE_BOOT_POLICY
> +	string "Integrity policy to apply on system startup"
> +	help
> +	  This option specifies a filepath to a IPE policy that is compiled

	                                      an IPE

> +	  into the kernel. This policy will be enforced until a policy update
> +	  is deployed via the $securityfs/ipe/policies/$policy_name/active
> +	  interface.

-- 
#Randy



More information about the Linux-security-module-archive mailing list