ima-policy: enable policy check

Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
This commit is contained in:
Lans Zhang
2017-07-04 17:21:48 +08:00
parent b736677f3f
commit a9e266c481

View File

@@ -22,3 +22,6 @@ appraise func=BPRM_CHECK euid=0 appraise_type=imasig
appraise func=MODULE_CHECK euid=0 appraise_type=imasig
appraise func=FIRMWARE_CHECK euid=0 appraise_type=imasig
# Enforce the coming policy write to be verified by IMA appraisal
appraise func=POLICY_CHECK euid=0 appraise_type=imasig