Re: [PATCH v7 5/5] certs: Allow root user to append signed hashes to the blacklist keyring

2021-03-17 Thread Mickaël Salaün
On 17/03/2021 15:48, Eric Snowberg wrote: > >> On Mar 15, 2021, at 12:01 PM, Mickaël Salaün wrote: >> >> >> On 15/03/2021 17:59, Eric Snowberg wrote: >>> On Mar 12, 2021, at 10:12 AM, Mickaël Salaün wrote: From: Mickaël Salaün Add a kernel option SYSTEM_BLACKLIST_AUTH

Re: [PATCH v7 5/5] certs: Allow root user to append signed hashes to the blacklist keyring

2021-03-17 Thread Eric Snowberg
> On Mar 15, 2021, at 12:01 PM, Mickaël Salaün wrote: > > > On 15/03/2021 17:59, Eric Snowberg wrote: >> >>> On Mar 12, 2021, at 10:12 AM, Mickaël Salaün wrote: >>> >>> From: Mickaël Salaün >>> >>> Add a kernel option SYSTEM_BLACKLIST_AUTH_UPDATE to enable the root user >>> to dynamically

Re: [PATCH v7 5/5] certs: Allow root user to append signed hashes to the blacklist keyring

2021-03-15 Thread Mickaël Salaün
On 15/03/2021 17:59, Eric Snowberg wrote: > >> On Mar 12, 2021, at 10:12 AM, Mickaël Salaün wrote: >> >> From: Mickaël Salaün >> >> Add a kernel option SYSTEM_BLACKLIST_AUTH_UPDATE to enable the root user >> to dynamically add new keys to the blacklist keyring. This enables to >> invalidate n

Re: [PATCH v7 5/5] certs: Allow root user to append signed hashes to the blacklist keyring

2021-03-15 Thread Eric Snowberg
> On Mar 12, 2021, at 10:12 AM, Mickaël Salaün wrote: > > From: Mickaël Salaün > > Add a kernel option SYSTEM_BLACKLIST_AUTH_UPDATE to enable the root user > to dynamically add new keys to the blacklist keyring. This enables to > invalidate new certificates, either from being loaded in a key

[PATCH v7 5/5] certs: Allow root user to append signed hashes to the blacklist keyring

2021-03-12 Thread Mickaël Salaün
From: Mickaël Salaün Add a kernel option SYSTEM_BLACKLIST_AUTH_UPDATE to enable the root user to dynamically add new keys to the blacklist keyring. This enables to invalidate new certificates, either from being loaded in a keyring, or from being trusted in a PKCS#7 certificate chain. This also