]> git.baikalelectronics.ru Git - kernel.git/commit
ima: define '_ima' as a builtin 'trusted' keyring
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Tue, 13 Aug 2013 12:47:43 +0000 (08:47 -0400)
committerMimi Zohar <zohar@linux.vnet.ibm.com>
Fri, 1 Nov 2013 00:20:48 +0000 (20:20 -0400)
commite5711947646d05bccbbfb6f052fa33e0002a2778
tree3a8a39da527431153698fc73640db47e8a1bd43a
parent27f49e5dcc7d4871086214636838ea811675f15a
ima: define '_ima' as a builtin 'trusted' keyring

Require all keys added to the IMA keyring be signed by an
existing trusted key on the system trusted keyring.

Changelog:
- define stub integrity_init_keyring() function (reported-by Fengguang Wu)
- differentiate between regular and trusted keyring names.
- replace printk with pr_info (D. Kasatkin)

Signed-off-by: Mimi Zohar <zohar@us.ibm.com>
security/integrity/digsig.c
security/integrity/ima/Kconfig
security/integrity/ima/ima_appraise.c
security/integrity/integrity.h