linux-integrity.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH v7 ima-evm-utils 0/2] make default hash algorithm dynamic
@ 2021-09-10 18:46 Bruno Meneguele
  2021-09-10 18:47 ` [PATCH v7 ima-evm-utils 1/2] set default hash algorithm in configuration time Bruno Meneguele
  2021-09-10 18:47 ` [PATCH v7 ima-evm-utils 2/2] make SHA-256 the default hash algorithm Bruno Meneguele
  0 siblings, 2 replies; 5+ messages in thread
From: Bruno Meneguele @ 2021-09-10 18:46 UTC (permalink / raw)
  To: zohar, Simon.THOBY, kgold; +Cc: linux-integrity, Bruno Meneguele

In order to allow users to set their own security policies, this patch
adds an option in configuration time to set the default hash algorithm to be
used. Considering that any hash algorithm supported by the kernel can be
used, the chosen algo is then checked against the hash_info.h header file.

At the same time, move from SHA1 to SHA256 default hash algorithm, following
the general movement of dropping SHA1 support in the major distros due to
its weaknesses.

Changelog:
v6 - make user input lower case regardless and rebase code
v5 - remove case insensitive grep
v4 - check against hash_info.h kernel header instead of /proc/crypto
v3 - remove wrong comment from m4 script
v2 - add a config time option for setting DEFAULT_HASH_ALGO.

Bruno Meneguele (2):
  set default hash algorithm in configuration time
  make SHA-256 the default hash algorithm

 README                  |  2 +-
 configure.ac            |  2 ++
 m4/default-hash-algo.m4 | 36 ++++++++++++++++++++++++++++++++++++
 src/evmctl.c            |  4 ++--
 src/imaevm.h            |  4 ++++
 src/libimaevm.c         |  2 +-
 6 files changed, 46 insertions(+), 4 deletions(-)
 create mode 100644 m4/default-hash-algo.m4

-- 
2.31.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2021-09-16 20:54 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-09-10 18:46 [PATCH v7 ima-evm-utils 0/2] make default hash algorithm dynamic Bruno Meneguele
2021-09-10 18:47 ` [PATCH v7 ima-evm-utils 1/2] set default hash algorithm in configuration time Bruno Meneguele
2021-09-14 15:24   ` Mimi Zohar
2021-09-16 20:54     ` Bruno Meneguele
2021-09-10 18:47 ` [PATCH v7 ima-evm-utils 2/2] make SHA-256 the default hash algorithm Bruno Meneguele

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).