From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.0 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 93E8EC433DF for ; Fri, 31 Jul 2020 08:02:24 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 76973207F5 for ; Fri, 31 Jul 2020 08:02:24 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731637AbgGaICY (ORCPT ); Fri, 31 Jul 2020 04:02:24 -0400 Received: from mx2.suse.de ([195.135.220.15]:45606 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731479AbgGaICY (ORCPT ); Fri, 31 Jul 2020 04:02:24 -0400 X-Virus-Scanned: by amavisd-new at test-mx.suse.de Received: from relay2.suse.de (unknown [195.135.221.27]) by mx2.suse.de (Postfix) with ESMTP id E75F0ADF2; Fri, 31 Jul 2020 08:02:35 +0000 (UTC) Date: Fri, 31 Jul 2020 10:02:21 +0200 From: Petr Vorel To: Lachlan Sneff Cc: zohar@linux.ibm.com, ltp@lists.linux.it, nramas@linux.microsoft.com, balajib@linux.microsoft.com, linux-integrity@vger.kernel.org Subject: Re: [PATCH] IMA: Add a test to verify importing a certificate into custom keyring Message-ID: <20200731080221.GA14041@dell5510> Reply-To: Petr Vorel References: <20200717205721.18173-1-t-josne@linux.microsoft.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20200717205721.18173-1-t-josne@linux.microsoft.com> Sender: linux-integrity-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-integrity@vger.kernel.org Hi Lachlan, > A test for verifying importing an x509 certificate into a keyring and > validating the key measurement performed by IMA is needed. I suppose you're going to send new version of this patch (rebased + fix according to Mimi's comments). IMHO that should be your last not yet merged patch. FYI: I'm planning to fix ima_tpm.sh and then implement autoloading IMA policy (when possible). Kind regards, Petr