OSDN Git Service

ima: enable loading of build time generated key on .ima keyring
authorNayna Jain <nayna@linux.ibm.com>
Fri, 9 Apr 2021 14:35:07 +0000 (10:35 -0400)
committerMimi Zohar <zohar@linux.ibm.com>
Fri, 9 Apr 2021 14:40:20 +0000 (10:40 -0400)
commit6cbdfb3d91bab122033bd2ecae8c259cb6e4f7d0
tree05c396347eaa59a17fe6819603f6eacc1cd546f9
parent0165f4ca223b04bb032095753fadd28816dc435f
ima: enable loading of build time generated key on .ima keyring

The kernel currently only loads the kernel module signing key onto the
builtin trusted keyring. Load the module signing key onto the IMA keyring
as well.

Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Acked-by: Stefan Berger <stefanb@linux.ibm.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
certs/system_certificates.S
certs/system_keyring.c
include/keys/system_keyring.h
security/integrity/digsig.c