Thread (5 messages) 5 messages, 2 authors, 2021-07-16

Re: [PATCH ima-evm-utils v9 0/3] ima-evm-utils: Add --keyid option

From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2021-07-16 21:58:39

On Fri, 2021-07-16 at 18:15 +0300, Vitaly Chikunov wrote:
Allow user to set signature's keyid using `--keyid' option. Keyid should
correspond to SKID in certificate. When keyid is calculated using SHA-1
in libimaevm it may mismatch keyid extracted by the kernel from SKID of
certificate (the way public key is presented to the kernel), thus making
signatures not verifiable. This may happen when certificate is using non
SHA-1 SKID (see rfc7093) or just 'unique number' (see rfc5280 4.2.1.2).
As a last resort user may specify arbitrary keyid using the new option.
Certificate filename could be used instead of the hex number with
`--keyid-from-cert' option. And, third option is to read keyid from the
cert appended to the key file.
Thanks, applied to next-integrity.

Mimi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help