ima: Remove deprecated IMA_TRUSTED_KEYRING Kconfig
authorNayna Jain <nayna@linux.ibm.com>
Tue, 11 Jul 2023 16:44:47 +0000 (12:44 -0400)
committerMimi Zohar <zohar@linux.ibm.com>
Tue, 1 Aug 2023 12:16:24 +0000 (08:16 -0400)
Time to remove "IMA_TRUSTED_KEYRING".

Fixes: f4dc37785e9b ("integrity: define '.evm' as a builtin 'trusted' keyring") # v4.5+
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
security/integrity/ima/Kconfig

index 60a511c6b583e23b2b8c59f8407ce4bb16ee208c..c17660bf5f3471aa17c628966d7cb6abe5b92d03 100644 (file)
@@ -248,18 +248,6 @@ config IMA_APPRAISE_MODSIG
           The modsig keyword can be used in the IMA policy to allow a hook
           to accept such signatures.
 
-config IMA_TRUSTED_KEYRING
-       bool "Require all keys on the .ima keyring be signed (deprecated)"
-       depends on IMA_APPRAISE && SYSTEM_TRUSTED_KEYRING
-       depends on INTEGRITY_ASYMMETRIC_KEYS
-       select INTEGRITY_TRUSTED_KEYRING
-       default y
-       help
-          This option requires that all keys added to the .ima
-          keyring be signed by a key on the system trusted keyring.
-
-          This option is deprecated in favor of INTEGRITY_TRUSTED_KEYRING
-
 config IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY
        bool "Permit keys validly signed by a built-in or secondary CA cert (EXPERIMENTAL)"
        depends on SYSTEM_TRUSTED_KEYRING