Thread (31 messages) 31 messages, 3 authors, 2021-09-09

Re: [PATCH v5 07/12] KEYS: Introduce link restriction to include builtin, secondary and machine keys

From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2021-09-09 17:27:18
Also in: keyrings, linux-crypto, linux-integrity, lkml

Hi Eric,

The subject line above is too long.   According to
Documentation/process/submitting-patches.rst the "the ``summary`` must
be no more than 70-75 characters".

On Tue, 2021-09-07 at 12:01 -0400, Eric Snowberg wrote:
quoted hunk ↗ jump to hunk
Introduce a new link restriction that includes the trusted builtin,
secondary and machine keys. The restriction is based on the key to be added
being vouched for by a key in any of these three keyrings.

Suggested-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Eric Snowberg <eric.snowberg@oracle.com>
---
v3: Initial version
v4: moved code under CONFIG_INTEGRITY_MOK_KEYRING
v5: Rename to machine keyring
---
 certs/system_keyring.c        | 23 +++++++++++++++++++++++
 include/keys/system_keyring.h |  6 ++++++
 2 files changed, 29 insertions(+)
diff --git a/certs/system_keyring.c b/certs/system_keyring.c
index 08ea542c8096..955bd57815f4 100644
--- a/certs/system_keyring.c
+++ b/certs/system_keyring.c
@@ -99,6 +99,29 @@ void __init set_machine_trusted_keys(struct key *keyring)
 {
 	machine_trusted_keys = keyring;
 }
+
+/**
+ * restrict_link_by_builtin_secondary_and_ca_trusted
Sorry for the patch churn.  With the keyring name change to ".machine",
the restriction name should also reflect this change.

thanks,

Mimi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help