Thread (32 messages) 32 messages, 6 authors, 2017-12-06

[Linux-ima-devel] [PATCH, RESEND 08/12] ima: added parser for RPM data type

flat view

From: jmorris@namei.org (James Morris)
Date: 2017-08-02 07:22:30
Also in: keyrings, linux-fsdevel, lkml

On Tue, 1 Aug 2017, Roberto Sassu wrote:
On 8/1/2017 12:27 PM, Christoph Hellwig wrote:
quoted
On Tue, Aug 01, 2017 at 12:20:36PM +0200, Roberto Sassu wrote:
quoted
This patch introduces a parser for RPM packages. It extracts the digests
from the RPMTAG_FILEDIGESTS header section and converts them to binary
data
before adding them to the hash table.

The advantage of this data type is that verifiers can determine who
produced that data, as headers are signed by Linux distributions vendors.
RPM headers signatures can be provided as digest list metadata.
Err, parsing arbitrary file formats has no business in the kernel.
The benefit of this choice is that no actions are required for
Linux distribution vendors to support the solution I'm proposing,
because they already provide signed digest lists (RPM headers).

Since the proof of loading a digest list is the digest of the
digest list (included in the list metadata), if RPM headers are
converted to a different format, remote attestation verifiers
cannot check the signature.

If the concern is security, it would be possible to prevent unsigned
RPM headers from being parsed, if the PGP key type is upstreamed
(adding in CC keyrings at vger.kernel.org).
It's a security concern and also a layering violation, there should be no 
need to parse package file formats in the kernel.

I'm not really clear on exactly how this patch series works.  Can you 
provide a more concrete explanation of what steps would occur during boot 
and attestation? 

-- 
James Morris
[off-list ref]

--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help