Thread (146 messages) 146 messages, 15 authors, 2017-12-07

[PATCH 03/27] Enforce module signatures if the kernel is locked down

From: Mimi Zohar <hidden>
Date: 2017-11-02 22:18:53
Also in: linux-efi, lkml

On Thu, 2017-11-02 at 22:01 +0000, David Howells wrote:
Mimi Zohar [off-list ref] wrote:
quoted
Right, it would never get here if the IMA signature verification
fails. ?If sig_enforce is not enabled, then it will also work. ?So the
only case is if sig_enforced is enabled and there is no key.

eg.
? ? ? ? ?else if (can_do_ima_check && is_ima_appraise_enabled())
? ? ? ? ? ? ? ? err = 0;
I'm not sure where you want to put that, but I can't just do this:

	/* Not having a signature is only an error if we're strict. */
	if (err == -ENOKEY && !sig_enforce &&
	    (!can_do_ima_check || !is_ima_appraise_enabled()) &&
The above IMA checks aren't needed here.
	    !kernel_is_locked_down("Loading of unsigned modules"))
		err = 0;
	else if (can_do_ima_check && is_ima_appraise_enabled())
		err = 0;

because that'll print out a message in lockdown mode saying that you're not
allowed to do that and then maybe do it anyway.
Then at least for now, document that even though kernel modules might
be signed and verified by IMA-appraisal, that in lockdown mode they
also require an appended signature.

Mimi

--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help