Thread (30 messages) 30 messages, 5 authors, 2018-03-16

[PATCH] security: Fix IMA Kconfig for dependencies on ARM64

From: jgg@ziepe.ca (Jason Gunthorpe)
Date: 2018-03-12 22:00:06
Also in: linux-integrity, lkml

On Mon, Mar 12, 2018 at 05:53:18PM -0400, Mimi Zohar wrote:
Using Kconfig to force the TPM to be builtin is not required, but
helpful. ?Users interested in IMA-measurement could configure the TPM
as builtin themselves. ?Without the TPM builtin, IMA goes into TPM-
bypass mode.
This issues, broadly speaking, we have lots of TPM drivers, selecting
only some to actually support IMA shows we have some kind of problem
here.

eg a distro on ARM should not have some TPM hardware work with IMA and
some fail just because of this kconfig.

IMHO if we want to do this, then IMA should completely disable modular
TPM drivers across the board.

Or, IMA folks need to figure out how to safely load TPM modules under
their constraints.

But this current kconfig approach is pretty weird..

Jason
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help