Re: [PATCH v3 2/2] Adds ima_root_ca keyring;

2015-10-09 Thread Petko Manolov
On 15-10-02 13:15:49, Mimi Zohar wrote: > On Thu, 2015-09-10 at 14:17 +0300, Petko Manolov wrote: > > The .system keyring is populated at kernel build time and read-only while > > the > > system is running. There is no way to dynamically add other user's CA so > > .ima_root_ca was introduced as

Re: [PATCH v3 2/2] Adds ima_root_ca keyring;

2015-10-02 Thread Mimi Zohar
On Thu, 2015-09-10 at 14:17 +0300, Petko Manolov wrote: > The .system keyring is populated at kernel build time and read-only while the > system is running. There is no way to dynamically add other user's CA so > .ima_root_ca was introduced as read-write keyring that stores these > certificates.