integrity, KEYS: add a reference to platform keyring
authorKairui Song <kasong@redhat.com>
Mon, 21 Jan 2019 09:59:28 +0000 (17:59 +0800)
committerMimi Zohar <zohar@linux.ibm.com>
Mon, 4 Feb 2019 22:29:19 +0000 (17:29 -0500)
commit219a3e8676f3132d27b530c7d2d6bcab89536b57
treea79baecc80144b604d059a6828057210c7a06b9e
parent2181e084b26bddca22bc3f23364c15809cfed28b
integrity, KEYS: add a reference to platform keyring

commit 9dc92c45177a ("integrity: Define a trusted platform keyring")
introduced a .platform keyring for storing preboot keys, used for
verifying kernel image signatures. Currently only IMA-appraisal is able
to use the keyring to verify kernel images that have their signature
stored in xattr.

This patch exposes the .platform keyring, making it accessible for
verifying PE signed kernel images as well.

Suggested-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Kairui Song <kasong@redhat.com>
Cc: David Howells <dhowells@redhat.com>
[zohar@linux.ibm.com: fixed checkpatch errors, squashed with patch fix]
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
certs/system_keyring.c
include/keys/system_keyring.h
security/integrity/digsig.c