-
- Downloads
KEYS: validate certificate trust only with builtin keys
Instead of allowing public keys, with certificates signed by any key on the system trusted keyring, to be added to a trusted keyring, this patch further restricts the certificates to those signed only by builtin keys on the system keyring. This patch defines a new option 'builtin' for the kernel parameter 'keys_ownerid' to allow trust validation using builtin keys. Simplified Mimi's "KEYS: define an owner trusted keyring" patch Changelog v7: - rename builtin_keys to use_builtin_keys Signed-off-by:Dmitry Kasatkin <d.kasatkin@samsung.com> Signed-off-by:
Mimi Zohar <zohar@linux.vnet.ibm.com>
Showing
- Documentation/kernel-parameters.txt 1 addition, 1 deletionDocumentation/kernel-parameters.txt
- crypto/asymmetric_keys/x509_public_key.c 6 additions, 3 deletionscrypto/asymmetric_keys/x509_public_key.c
- include/linux/key.h 1 addition, 0 deletionsinclude/linux/key.h
- kernel/system_keyring.c 1 addition, 0 deletionskernel/system_keyring.c
Loading
Please register or sign in to comment