summaryrefslogtreecommitdiffstats
path: root/security/integrity/iint.c
diff options
context:
space:
mode:
authorDmitry Kasatkin2015-10-22 20:26:21 +0200
committerMimi Zohar2015-12-15 14:31:19 +0100
commit2ce523eb8976a12de1a4fb6fe8ad0b09b5dafb31 (patch)
tree45b99ce12be798b8d4d75eadefd576d2aa430efe /security/integrity/iint.c
parentintegrity: define '.evm' as a builtin 'trusted' keyring (diff)
downloadkernel-qcow2-linux-2ce523eb8976a12de1a4fb6fe8ad0b09b5dafb31.tar.gz
kernel-qcow2-linux-2ce523eb8976a12de1a4fb6fe8ad0b09b5dafb31.tar.xz
kernel-qcow2-linux-2ce523eb8976a12de1a4fb6fe8ad0b09b5dafb31.zip
evm: load an x509 certificate from the kernel
This patch defines a configuration option and the evm_load_x509() hook to load an X509 certificate onto the EVM trusted kernel keyring. Changes in v4: * Patch description updated Changes in v3: * Removed EVM_X509_PATH definition. CONFIG_EVM_X509_PATH is used directly. Changes in v2: * default key patch changed to /etc/keys Signed-off-by: Dmitry Kasatkin <dmitry.kasatkin@huawei.com> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Diffstat (limited to 'security/integrity/iint.c')
-rw-r--r--security/integrity/iint.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/security/integrity/iint.c b/security/integrity/iint.c
index 3d2f5b45c8cb..2de9c820903f 100644
--- a/security/integrity/iint.c
+++ b/security/integrity/iint.c
@@ -254,4 +254,5 @@ out:
void __init integrity_load_keys(void)
{
ima_load_x509();
+ evm_load_x509();
}