Thread (24 messages) 24 messages, 3 authors, 2019-07-07

Re: [PATCH v6 13/17] fs-verity: support builtin file signatures

From: "Theodore Ts'o" <tytso@mit.edu>
Date: 2019-07-07 18:47:48
Also in: linux-ext4, linux-f2fs-devel, linux-fscrypt, linux-fsdevel, linux-integrity

On Mon, Jul 01, 2019 at 08:32:33AM -0700, Eric Biggers wrote:
From: Eric Biggers <redacted>

To meet some users' needs, add optional support for having fs-verity
handle a portion of the authentication policy in the kernel.  An
".fs-verity" keyring is created to which X.509 certificates can be
added; then a sysctl 'fs.verity.require_signatures' can be set to cause
the kernel to enforce that all fs-verity files contain a signature of
their file measurement by a key in this keyring.

See the "Built-in signature verification" section of
Documentation/filesystems/fsverity.rst for the full documentation.

Signed-off-by: Eric Biggers <redacted>
Looks good, you can add:

Reviewed-by: Theodore Ts'o <tytso@mit.edu>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help