]> git.baikalelectronics.ru Git - kernel.git/commit
kexec, KEYS: Make use of platform keyring for signature verify
authorKairui Song <kasong@redhat.com>
Mon, 21 Jan 2019 09:59:29 +0000 (17:59 +0800)
committerMimi Zohar <zohar@linux.ibm.com>
Mon, 4 Feb 2019 22:34:07 +0000 (17:34 -0500)
commitdf649a59fa423e2f04fc274bcdef00c00db8e47a
treec322d3e96510244468ed35ea2f612dd71f7035ad
parente763f1a0bd5dcf213e0560971e38037da33dd2d6
kexec, KEYS: Make use of platform keyring for signature verify

This patch allows the kexec_file_load syscall to verify the PE signed
kernel image signature based on the preboot keys stored in the .platform
keyring, as fall back, if the signature verification failed due to not
finding the public key in the secondary or builtin keyrings.

This commit adds a VERIFY_USE_PLATFORM_KEYRING similar to previous
VERIFY_USE_SECONDARY_KEYRING indicating that verify_pkcs7_signature
should verify the signature using platform keyring.  Also, decrease
the error message log level when verification failed with -ENOKEY,
so that if called tried multiple time with different keyring it
won't generate extra noises.

Signed-off-by: Kairui Song <kasong@redhat.com>
Cc: David Howells <dhowells@redhat.com>
Acked-by: Dave Young <dyoung@redhat.com> (for kexec_file_load part)
[zohar@linux.ibm.com: tweaked the first paragraph of the patch description,
 and fixed checkpatch warning.]
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
arch/x86/kernel/kexec-bzimage64.c
certs/system_keyring.c
include/linux/verification.h