Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1625619
| From | Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 0/6] Appended signatures support for IMA appraisal |
| Date | 2017-04-18 22:20 +0200 |
| Message-ID | <txHLr-267-1@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
On the OpenPOWER platform, secure boot and trusted boot are being implemented using IMA for taking measurements and verifying signatures. Since the kernel image on Power servers is an ELF binary, kernels are signed using the scripts/sign-file tool and thus use the same signature format as signed kernel modules. This patch series adds support in IMA for verifying those signatures. It adds flexibility to OpenPOWER secure boot, because it can boot kernels with the signature appended to them as well as kernels where the signature is stored in the IMA extended attribute. The first four patches are cleanups and improvements that can be taken independently from the others (and from each other as well). The last two are the ones actually focused on this feature. These patches apply on top of today's linux-security/next. Thiago Jung Bauermann (6): integrity: Small code improvements ima: Tidy up constant strings ima: Simplify policy_func_show. ima: Log the same audit cause whenever a file has no signature MODSIGN: Export module signature definitions. ima: Support appended signatures for appraisal crypto/asymmetric_keys/asymmetric_type.c | 1 + crypto/asymmetric_keys/pkcs7_parser.c | 12 +++++ crypto/asymmetric_keys/pkcs7_verify.c | 13 +++++ include/crypto/pkcs7.h | 3 ++ include/linux/module_signature.h | 45 ++++++++++++++++ include/linux/verification.h | 1 + init/Kconfig | 6 ++- kernel/Makefile | 2 +- kernel/module_signing.c | 74 +++++++++++---------------- security/integrity/Kconfig | 2 +- security/integrity/digsig_asymmetric.c | 4 +- security/integrity/iint.c | 2 +- security/integrity/ima/Kconfig | 13 +++++ security/integrity/ima/ima.h | 8 +++ security/integrity/ima/ima_appraise.c | 86 ++++++++++++++++++++++++++++++- security/integrity/ima/ima_init.c | 2 +- security/integrity/ima/ima_main.c | 30 +++++++++-- security/integrity/ima/ima_policy.c | 88 ++++++++++++-------------------- security/integrity/integrity.h | 27 ++++++---- 19 files changed, 302 insertions(+), 117 deletions(-) create mode 100644 include/linux/module_signature.h -- 2.7.4
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[PATCH 0/6] Appended signatures support for IMA appraisal Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:20 +0200
[PATCH 5/6] MODSIGN: Export module signature definitions. Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:20 +0200
Re: [PATCH 5/6] MODSIGN: Export module signature definitions. Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-20 14:40 +0200
Re: [PATCH 5/6] MODSIGN: Export module signature definitions. David Howells <dhowells@redhat.com> - 2017-04-20 16:40 +0200
Re: [PATCH 5/6] MODSIGN: Export module signature definitions. Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-20 23:10 +0200
[PATCH 2/6] ima: Tidy up constant strings Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:20 +0200
[PATCH 3/6] ima: Simplify policy_func_show. Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:20 +0200
Re: [PATCH 3/6] ima: Simplify policy_func_show. Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-20 14:20 +0200
Re: [PATCH 3/6] ima: Simplify policy_func_show. Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-20 22:50 +0200
Re: [PATCH 3/6] ima: Simplify policy_func_show. Mimi Zohar <zohar@linux.vnet.ibm.com> - 2017-04-21 16:00 +0200
Re: [PATCH 3/6] ima: Simplify policy_func_show. Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-24 19:20 +0200
[PATCH 1/6] integrity: Small code improvements Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:20 +0200
[PATCH 4/6] ima: Log the same audit cause whenever a file has no signature Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:30 +0200
[PATCH 6/6] ima: Support appended signatures for appraisal Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-18 22:30 +0200
Re: [PATCH 6/6] ima: Support appended signatures for appraisal kbuild test robot <lkp@intel.com> - 2017-04-20 05:10 +0200
Re: [PATCH 6/6] ima: Support appended signatures for appraisal Thiago Jung Bauermann <bauerman@linux.vnet.ibm.com> - 2017-04-21 01:50 +0200
csiph-web