[PATCH 3/3] ima: based on policy require signed kexec kernel images

2018-05-10 Thread Mimi Zohar
The original kexec_load syscall can not verify file signatures. This patch differentiates between the kexec_load and kexec_file_load syscalls. Signed-off-by: Mimi Zohar Cc: Eric Biederman Cc: David Howells Cc: Kees Cook

[PATCH 3/3] ima: based on policy require signed kexec kernel images

2018-05-10 Thread Mimi Zohar
The original kexec_load syscall can not verify file signatures. This patch differentiates between the kexec_load and kexec_file_load syscalls. Signed-off-by: Mimi Zohar Cc: Eric Biederman Cc: David Howells Cc: Kees Cook Cc: Matthew Garrett --- security/integrity/ima/ima.h| 1 +

[PATCH 3/3] ima: based on policy require signed kexec kernel images

2018-04-12 Thread Mimi Zohar
The original kexec_load syscall can not verify file signatures. This patch differentiates between the kexec_load and kexec_file_load syscalls. Signed-off-by: Mimi Zohar --- security/integrity/ima/ima.h| 1 + security/integrity/ima/ima_main.c | 9 +

[PATCH 3/3] ima: based on policy require signed kexec kernel images

2018-04-12 Thread Mimi Zohar
The original kexec_load syscall can not verify file signatures. This patch differentiates between the kexec_load and kexec_file_load syscalls. Signed-off-by: Mimi Zohar --- security/integrity/ima/ima.h| 1 + security/integrity/ima/ima_main.c | 9 +