Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1306946

Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings

From Mimi Zohar <zohar@linux.vnet.ibm.com>
Newsgroups linux.kernel
Subject Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings
Date 2016-01-12 03:50 +0100
Message-ID <qPXbX-30c-3@gated-at.bofh.it> (permalink)
References <qOKTw-2Pp-21@gated-at.bofh.it> <qOK78-2eA-21@gated-at.bofh.it> <qOKqu-2lS-25@gated-at.bofh.it> <qPVa9-1En-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, 2016-01-12 at 00:38 +0000, David Howells wrote:
> Mimi Zohar <zohar@linux.vnet.ibm.com> wrote:
> 
> > Back in November, Mehmet Kayaalp posted a patch for safely adding
> > additional keys to the system keyring post build and a tool for
> > re-signing the kernel.
> > 
> > https://www.mail-archive.com/linux-security-module@vger.kernel.org/msg03679.html
> 
> That's irrelevant to this particular discussion.

Not really.  The discussion centers around the system keyring and the
origin of the keys on it.  These patches safely allow additional keys to
be added post-build to the system keyring.

> And, yes, I should deal with
> his patch.

Thank you.

Mimi

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 10/15] X.509: Extract signature digest and make  self-signed cert checks earlier David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 03/15] KEYS: Generalise system_verify_data() to provide  access to internal content David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 05/15] KEYS: Add an alloc flag to convey the builtinness  of a key David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 12/15] X.509: Move the trust validation code out to its  own file David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 11/15] PKCS#7: Make the signature a pointer rather than  embedding it David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 01/15] X.509: Partially revert patch to add validation  against IMA MOK keyring David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 06/15] KEYS: Add a facility to restrict new links into a  keyring David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 02/15] X.509: Don't treat self-signed keys specially David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  [RFC PATCH 07/15] KEYS: Allow authentication data to be stored in  an asymmetric key David Howells <dhowells@redhat.com> - 2016-01-08 19:40 +0100
  Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-08 20:00 +0100
    Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-08 20:30 +0100
      Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-12 01:40 +0100
        Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings Mimi Zohar <zohar@linux.vnet.ibm.com> - 2016-01-12 03:50 +0100
    Re: [RFC PATCH 00/15] KEYS: Restrict additions to 'trusted' keyrings David Howells <dhowells@redhat.com> - 2016-01-12 01:40 +0100

csiph-web