Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1304899

[RFC PATCH 01/15] X.509: Partially revert patch to add validation against IMA MOK keyring

From David Howells <dhowells@redhat.com>
Newsgroups linux.kernel
Subject [RFC PATCH 01/15] X.509: Partially revert patch to add validation against IMA MOK keyring
Date 2016-01-08 19:40 +0100
Message-ID <qOK7b-2eA-91@gated-at.bofh.it> (permalink)
References <qOK78-2eA-21@gated-at.bofh.it>
Organization Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903

Show all headers | View raw


Partially revert commit 41c89b64d7184a780f12f2cccdabe65cb2408893:

	Author: Petko Manolov <petkan@mip-labs.com>
	Date:   Wed Dec 2 17:47:55 2015 +0200
	IMA: create machine owner and blacklist keyrings

The problem is that prep->trusted is a simple boolean and the additional
x509_validate_trust() call doesn't therefore distinguish levels of
trustedness, but is just OR'd with the result of validation against the
system trusted keyring.

However, setting the trusted flag means that this key may be added to *any*
trusted-only keyring - including the system trusted keyring.

Whilst I appreciate what the patch is trying to do, I don't think this is
quite the right solution.

Signed-off-by: David Howells <dhowells@redhat.com>
cc: Petko Manolov <petkan@mip-labs.com>
cc: Mimi Zohar <zohar@linux.vnet.ibm.com>
cc: keyrings@vger.kernel.org
---

 crypto/asymmetric_keys/x509_public_key.c |    2 --
 1 file changed, 2 deletions(-)

diff --git a/crypto/asymmetric_keys/x509_public_key.c b/crypto/asymmetric_keys/x509_public_key.c
index 9e9e5a6a9ed6..2a44b3752471 100644
--- a/crypto/asymmetric_keys/x509_public_key.c
+++ b/crypto/asymmetric_keys/x509_public_key.c
@@ -321,8 +321,6 @@ static int x509_key_preparse(struct key_preparsed_payload *prep)
 			goto error_free_cert;
 	} else if (!prep->trusted) {
 		ret = x509_validate_trust(cert, get_system_trusted_keyring());
-		if (ret)
-			ret = x509_validate_trust(cert, get_ima_mok_keyring());
 		if (!ret)
 			prep->trusted = 1;
 	}

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 10/15] X.509: Extract signature digest and make  self-signed cert checks earlier David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 03/15] KEYS: Generalise system_verify_data() to provide  access to internal content David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 05/15] KEYS: Add an alloc flag to convey the builtinness  of a key David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 12/15] X.509: Move the trust validation code out to its  own file David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 11/15] PKCS#7: Make the signature a pointer rather than  embedding it David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 01/15] X.509: Partially revert patch to add validation  against IMA MOK keyring David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 06/15] KEYS: Add a facility to restrict new links into a  keyring David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 02/15] X.509: Don't treat self-signed keys specially David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 07/15] KEYS: Allow authentication data to be stored in  an asymmetric key David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-08 20:00 +0100
    Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-08 20:30 +0100
      Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-12 01:40 +0100
        Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-12 03:50 +0100
    Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-12 01:40 +0100

csiph-web