Re: [PATCH v1] dm verity: Add support for signature verification with 2nd keyring

2020-10-13 Thread Mickaël Salaün
On 13/10/2020 01:55, Jarkko Sakkinen wrote: > On Fri, Oct 09, 2020 at 11:50:03AM +0200, Mickaël Salaün wrote: >> Hi, >> >> What do you think about this patch? >> >> Regards, >> Mickaël >> >> On 02/10/2020 09:18, Mickaël Salaün wrote: >>> From: Mickaël Salaün >>> >>> Add a new DM_VERITY_VERIFY_R

Re: [PATCH v1] dm verity: Add support for signature verification with 2nd keyring

2020-10-12 Thread Jarkko Sakkinen
On Fri, Oct 09, 2020 at 11:50:03AM +0200, Mickaël Salaün wrote: > Hi, > > What do you think about this patch? > > Regards, > Mickaël > > On 02/10/2020 09:18, Mickaël Salaün wrote: > > From: Mickaël Salaün > > > > Add a new DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING configuration > > to e

Re: [PATCH v1] dm verity: Add support for signature verification with 2nd keyring

2020-10-09 Thread Mickaël Salaün
Hi, What do you think about this patch? Regards, Mickaël On 02/10/2020 09:18, Mickaël Salaün wrote: > From: Mickaël Salaün > > Add a new DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING configuration > to enable dm-verity signatures to be verified against the secondary > trusted keyring. This

[PATCH v1] dm verity: Add support for signature verification with 2nd keyring

2020-10-02 Thread Mickaël Salaün
From: Mickaël Salaün Add a new DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING configuration to enable dm-verity signatures to be verified against the secondary trusted keyring. This allows certificate updates without kernel update and reboot, aligning with module and kernel (kexec) signature ve