mirror of
https://git.yoctoproject.org/meta-security
synced 2026-05-08 05:09:48 +00:00
meta-integrity: remove kernel fragments now in cache
Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
@@ -1,6 +1,5 @@
|
|||||||
FILESEXTRAPATHS_prepend := "${THISDIR}/linux:"
|
KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "ima", " features/ima/ima.scc", "" ,d)}"
|
||||||
|
|
||||||
SRC_URI += "${@bb.utils.contains('DISTRO_FEATURES', 'ima', ' file://ima.cfg', '', d)}"
|
KERNEL_FEATURES_append = " ${@bb.utils.contains('DISTRO_FEATURES', 'modsign', ' features/ima/modsign.scc', '', d)}"
|
||||||
SRC_URI += "${@bb.utils.contains('DISTRO_FEATURES', 'modsign', ' file://modsign.scc file://modsign.cfg', '', d)}"
|
|
||||||
|
|
||||||
inherit ${@bb.utils.contains('DISTRO_FEATURES', 'modsign', 'kernel-modsign', '', d)}
|
inherit ${@bb.utils.contains('DISTRO_FEATURES', 'modsign', 'kernel-modsign', '', d)}
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
CONFIG_IMA=y
|
|
||||||
CONFIG_IMA_MEASURE_PCR_IDX=10
|
|
||||||
CONFIG_IMA_NG_TEMPLATE=y
|
|
||||||
CONFIG_IMA_DEFAULT_TEMPLATE="ima-ng"
|
|
||||||
CONFIG_IMA_DEFAULT_HASH_SHA1=y
|
|
||||||
CONFIG_IMA_DEFAULT_HASH="sha1"
|
|
||||||
CONFIG_IMA_APPRAISE=y
|
|
||||||
CONFIG_IMA_APPRAISE_BOOTPARAM=y
|
|
||||||
CONFIG_IMA_TRUSTED_KEYRING=y
|
|
||||||
CONFIG_SIGNATURE=y
|
|
||||||
CONFIG_IMA_WRITE_POLICY=y
|
|
||||||
CONFIG_IMA_READ_POLICY=y
|
|
||||||
CONFIG_IMA_LOAD_X509=y
|
|
||||||
CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der"
|
|
||||||
|
|
||||||
#CONFIG_INTEGRITY_SIGNATURE=y
|
|
||||||
#CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
|
|
||||||
#CONFIG_INTEGRITY_TRUSTED_KEYRING=y
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
# CONFIG_IMA_APPRAISE_SIGNED_INIT is not set
|
|
||||||
CONFIG_EVM_LOAD_X509=y
|
|
||||||
CONFIG_EVM_X509_PATH="/etc/keys/x509_evm.der"
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
CONFIG_MODULE_SIG=y
|
|
||||||
CONFIG_MODULE_SIG_FORCE=y
|
|
||||||
CONFIG_MODULE_SIG_SHA256=y
|
|
||||||
CONFIG_MODULE_SIG_HASH="sha256"
|
|
||||||
CONFIG_MODULE_SIG_KEY="modsign_key.pem"
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
define KFEATURE_DESCRIPTION "Kernel Module Signing (modsign) enablement"
|
|
||||||
define KFEATURE_COMPATIBILITY all
|
|
||||||
|
|
||||||
kconf non-hardware modsign.cfg
|
|
||||||
Reference in New Issue
Block a user