Re:[RFC 1/1] Add dm verity root hash pkcs7 sig validation.

2019-06-03 Thread jaskarankhurana
On Tue, 21 May 2019, Milan Broz wrote: On 20/05/2019 23:54, Jaskaran Khurana wrote: Adds in-kernel pkcs7 signature checking for the roothash of the dm-verity hash tree. Adds DM_VERITY_VERIFY_ROOTHASH_SIG_FORCE: roothash signature *must* be specified for all dm verity volumes and

Re: [RFC 1/1] Add dm verity root hash pkcs7 sig validation.

2019-05-20 Thread Singh, Balbir
On 5/21/19 7:54 AM, Jaskaran Khurana wrote: > Adds in-kernel pkcs7 signature checking for the roothash of > the dm-verity hash tree. > > The verification is to support cases where the roothash is not secured by > Trusted Boot, UEFI Secureboot or similar technologies. > One of the use cases for