On Mon, 2019-03-11 at 09:34 +0100, Petr Vorel wrote:
> Hi Mimi,
>
> > On Thu, 2019-02-28 at 23:00 +0100, Petr Vorel wrote:
>
> > > > + local keypair1="$2"
> > > > + local keypair2="$3"
> > > > +
> > > > + mount_securityfs
> > > > +
> > > > + local ima_policy=$SECURITYFS/im
Hi Mimi,
> On Thu, 2019-02-28 at 23:00 +0100, Petr Vorel wrote:
> > > + local keypair1="$2"
> > > + local keypair2="$3"
> > > +
> > > + mount_securityfs
> > > +
> > > + local ima_policy=$SECURITYFS/ima/policy
> > > + if [ ! -e $ima_policy ]; then
> > > + log_fail "$ima_policy not found"
>
On Thu, 2019-02-28 at 23:00 +0100, Petr Vorel wrote:
> > + local keypair1="$2"
> > + local keypair2="$3"
> > +
> > + mount_securityfs
> > +
> > + local ima_policy=$SECURITYFS/ima/policy
> > + if [ ! -e $ima_policy ]; then
> > + log_fail "$ima_policy not found"
> > + fi
> > +
Hi Mimi,
> The kernel can be configured to verify PE signed kernel images, IMA
> kernel image signatures, both types of signatures, or none. This test
> verifies only properly signed kernel images are loaded into memory,
> based on the kernel configuration and runtime policies.
> Signed-off-by:
Hi Mimi,
> The kernel can be configured to verify PE signed kernel images, IMA
> kernel image signatures, both types of signatures, or none. This test
> verifies only properly signed kernel images are loaded into memory,
> based on the kernel configuration and runtime policies.
> Signed-off-by:
On 2/26/19 4:26 PM, Mimi Zohar wrote:
The kernel can be configured to verify PE signed kernel images, IMA
kernel image signatures, both types of signatures, or none. This test
verifies only properly signed kernel images are loaded into memory,
based on the kernel configuration and runtime polici
The kernel can be configured to verify PE signed kernel images, IMA
kernel image signatures, both types of signatures, or none. This test
verifies only properly signed kernel images are loaded into memory,
based on the kernel configuration and runtime policies.
Signed-off-by: Mimi Zohar
---
too
7 matches
Mail list logo