Thread (26 messages) 26 messages, 5 authors, 2022-02-14

Re: [PATCH v5 2/6] powerpc/kexec_file: Add KEXEC_SIG support.

From: Mimi Zohar <zohar@linux.ibm.com>
Date: 2022-02-14 03:01:03
Also in: kexec, keyrings, linux-crypto, linux-integrity, linux-s390, linux-security-module, lkml

Hi Michal,

On Tue, 2022-01-11 at 12:37 +0100, Michal Suchanek wrote:
quoted hunk ↗ jump to hunk
diff --git a/arch/powerpc/Kconfig b/arch/powerpc/Kconfig
index dea74d7717c0..1cde9b6c5987 100644
--- a/arch/powerpc/Kconfig
+++ b/arch/powerpc/Kconfig
@@ -560,6 +560,22 @@ config KEXEC_FILE
 config ARCH_HAS_KEXEC_PURGATORY
        def_bool KEXEC_FILE
 
+config KEXEC_SIG
+       bool "Verify kernel signature during kexec_file_load() syscall"
+       depends on KEXEC_FILE && MODULE_SIG_FORMAT
+       help
+         This option makes kernel signature verification mandatory for
+         the kexec_file_load() syscall.
When KEXEC_SIG is enabled on other architectures, IMA does not define a
kexec 'appraise' policy rule.  Refer to the policy rules in
security/ima/ima_efi.c.  Similarly the kexec 'appraise' policy rule in
arch/powerpc/kernel/ima_policy.c should not be defined.

-- 
thanks,

Mimi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help