]> git.baikalelectronics.ru Git - kernel.git/commit
integrity: Do not load MOK and MOKx when secure boot be disabled
authorLee, Chun-Yi <joeyli.kernel@gmail.com>
Sat, 18 Dec 2021 02:09:05 +0000 (10:09 +0800)
committerMimi Zohar <zohar@linux.ibm.com>
Fri, 24 Dec 2021 15:25:24 +0000 (10:25 -0500)
commit1c399861c45ec24c7c630543635aa4ce73b309fb
tree7cab118eacabaecc222cbc63040de48a016005ee
parent3b5ac6539b3f99b9ee8376112135226c2bcedf4e
integrity: Do not load MOK and MOKx when secure boot be disabled

The security of Machine Owner Key (MOK) relies on secure boot. When
secure boot is disabled, EFI firmware will not verify binary code. Then
arbitrary efi binary code can modify MOK when rebooting.

This patch prevents MOK/MOKx be loaded when secure boot be disabled.

Signed-off-by: "Lee, Chun-Yi" <jlee@suse.com>
Reviewed-by: Petr Vorel <pvorel@suse.cz>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
security/integrity/platform_certs/load_uefi.c