All of lore.kernel.org
 help / color / mirror / Atom feed
* [RFC PATCH 0/1] KEYS, integrity: Link .platform keyring to .secondary_trusted_keys
@ 2019-01-08  8:12 ` Kairui Song
  0 siblings, 0 replies; 20+ messages in thread
From: Kairui Song @ 2019-01-08  8:12 UTC (permalink / raw)
  To: linux-kernel
  Cc: dhowells, dwmw2, jwboyer, keyrings, jmorris, serge, zohar,
	bauerman, ebiggers, nayna, dyoung, Kairui Song

Hi, as the subject, this is a patch that links the new introduced
.platform keyring into .secondary_trusted_keys keyring. This is
mainly for the kexec_file_load, make kexec_file_load be able to verify
the kernel image agains keys provided by platform or firmware.
kexec_file_load already could verify the image agains secondary_trusted_keys
if secondary_trusted_keys exits, so this will make kexec_file_load be ware
of platform keys as well.

This may also useful for things like module sign verify that are using
secondary_trusted_keys. I'm not sure if it will be better to move the
INTEGRITY_PLATFORM_KEYRING to certs/ and let integrity subsystem use
the keyring there, so just linked the .platform keyring into kernel's
.secondary_trusted_keys keyring.

It workd for my case, tested in a VM, I signed the kernel image locally
with pesign and imported the cert to EFI's MokList variable.

Kairui Song (1):
  KEYS, integrity: Link .platform keyring to .secondary_trusted_keys

 certs/system_keyring.c          | 30 ++++++++++++++++++++++++++++++
 include/keys/platform_keyring.h | 12 ++++++++++++
 security/integrity/digsig.c     |  7 +++++++
 3 files changed, 49 insertions(+)
 create mode 100644 include/keys/platform_keyring.h

-- 
2.20.1

^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2019-01-17 16:16 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-01-08  8:12 [RFC PATCH 0/1] KEYS, integrity: Link .platform keyring to .secondary_trusted_keys Kairui Song
2019-01-08  8:12 ` Kairui Song
2019-01-08  8:12 ` [RFC PATCH 1/1] " Kairui Song
2019-01-08  8:12   ` Kairui Song
2019-01-08 15:18   ` Mimi Zohar
2019-01-08 15:18     ` Mimi Zohar
2019-01-09  1:33     ` Dave Young
2019-01-09  1:33       ` Dave Young
2019-01-09  1:33       ` Dave Young
2019-01-09  2:02       ` Kairui Song
2019-01-09  2:02         ` Kairui Song
2019-01-09  2:02         ` Kairui Song
2019-01-09 14:07       ` Mimi Zohar
2019-01-09 14:07         ` Mimi Zohar
2019-01-09 14:07         ` Mimi Zohar
2019-01-08 14:31 ` [RFC PATCH 0/1] " Mimi Zohar
2019-01-08 14:31   ` Mimi Zohar
2019-01-17 15:04 ` [RFC PATCH 1/1] " David Howells
2019-01-17 16:15   ` Kairui Song
2019-01-17 16:15     ` Kairui Song

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.