summaryrefslogtreecommitdiffstats
path: root/security/integrity/ima/Kconfig
diff options
context:
space:
mode:
authorMimi Zohar2017-04-25 04:06:49 +0200
committerMimi Zohar2017-06-21 20:37:12 +0200
commite1f5e01f4b035ced1c71b40866e4e5c0508fbb0b (patch)
treed17fa7316999c9dd88e05d061c2d34b168f54661 /security/integrity/ima/Kconfig
parentima: define a set of appraisal rules requiring file signatures (diff)
downloadkernel-qcow2-linux-e1f5e01f4b035ced1c71b40866e4e5c0508fbb0b.tar.gz
kernel-qcow2-linux-e1f5e01f4b035ced1c71b40866e4e5c0508fbb0b.tar.xz
kernel-qcow2-linux-e1f5e01f4b035ced1c71b40866e4e5c0508fbb0b.zip
ima: define Kconfig IMA_APPRAISE_BOOTPARAM option
Permit enabling the different "ima_appraise=" modes (eg. log, fix) from the boot command line. Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Diffstat (limited to 'security/integrity/ima/Kconfig')
-rw-r--r--security/integrity/ima/Kconfig8
1 files changed, 8 insertions, 0 deletions
diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index 370eb2f4dd37..8b688a26033d 100644
--- a/security/integrity/ima/Kconfig
+++ b/security/integrity/ima/Kconfig
@@ -155,6 +155,14 @@ config IMA_APPRAISE
<http://linux-ima.sourceforge.net>
If unsure, say N.
+config IMA_APPRAISE_BOOTPARAM
+ bool "ima_appraise boot parameter"
+ depends on IMA_APPRAISE
+ default y
+ help
+ This option enables the different "ima_appraise=" modes
+ (eg. fix, log) from the boot command line.
+
config IMA_TRUSTED_KEYRING
bool "Require all keys on the .ima keyring be signed (deprecated)"
depends on IMA_APPRAISE && SYSTEM_TRUSTED_KEYRING