]> git.baikalelectronics.ru Git - kernel.git/commit
integrity: Move import of MokListRT certs to a separate routine
authorLenny Szubowicz <lszubowi@redhat.com>
Sat, 5 Sep 2020 01:31:06 +0000 (21:31 -0400)
committerArd Biesheuvel <ardb@kernel.org>
Wed, 16 Sep 2020 15:53:42 +0000 (18:53 +0300)
commit42e56796d29d4214e47709e4be84d28d495c1823
treed141f50253f8b2d14223f79fe401d6f6129feec2
parent56fdc3f15b2a4f05a42126d486025dab1531b1cc
integrity: Move import of MokListRT certs to a separate routine

Move the loading of certs from the UEFI MokListRT into a separate
routine to facilitate additional MokList functionality.

There is no visible functional change as a result of this patch.
Although the UEFI dbx certs are now loaded before the MokList certs,
they are loaded onto different key rings. So the order of the keys
on their respective key rings is the same.

Signed-off-by: Lenny Szubowicz <lszubowi@redhat.com>
Reviewed-by: Mimi Zohar <zohar@linux.ibm.com>
Link: https://lore.kernel.org/r/20200905013107.10457-3-lszubowi@redhat.com
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
security/integrity/platform_certs/load_uefi.c