mirror of
https://git.yoctoproject.org/meta-security
synced 2026-05-30 12:30:36 +00:00
ima.cfg: update to 5.0 kernel
Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
@@ -1,16 +1,18 @@
|
|||||||
# Enable bare minimum IMA measurement and appraisal as needed by this layer.
|
|
||||||
|
|
||||||
CONFIG_SECURITY=y
|
|
||||||
CONFIG_INTEGRITY=y
|
|
||||||
|
|
||||||
# measurement
|
|
||||||
CONFIG_IMA=y
|
CONFIG_IMA=y
|
||||||
|
CONFIG_IMA_MEASURE_PCR_IDX=10
|
||||||
# appraisal
|
CONFIG_IMA_NG_TEMPLATE=y
|
||||||
|
CONFIG_IMA_DEFAULT_TEMPLATE="ima-ng"
|
||||||
|
CONFIG_IMA_DEFAULT_HASH_SHA1=y
|
||||||
|
CONFIG_IMA_DEFAULT_HASH="sha1"
|
||||||
CONFIG_IMA_APPRAISE=y
|
CONFIG_IMA_APPRAISE=y
|
||||||
CONFIG_INTEGRITY_SIGNATURE=y
|
CONFIG_IMA_APPRAISE_BOOTPARAM=y
|
||||||
CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
|
|
||||||
|
|
||||||
# Kernel will get built with embedded X.509 root CA key and all keys
|
|
||||||
# need to be signed with that.
|
|
||||||
CONFIG_IMA_TRUSTED_KEYRING=y
|
CONFIG_IMA_TRUSTED_KEYRING=y
|
||||||
|
CONFIG_SIGNATURE=y
|
||||||
|
CONFIG_IMA_WRITE_POLICY=y
|
||||||
|
CONFIG_IMA_READ_POLICY=y
|
||||||
|
CONFIG_IMA_LOAD_X509=y
|
||||||
|
CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der"
|
||||||
|
|
||||||
|
#CONFIG_INTEGRITY_SIGNATURE=y
|
||||||
|
#CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
|
||||||
|
#CONFIG_INTEGRITY_TRUSTED_KEYRING=y
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
CONFIG_KEYS=y
|
# CONFIG_IMA_APPRAISE_SIGNED_INIT is not set
|
||||||
CONFIG_SYSTEM_TRUSTED_KEYRING=y
|
CONFIG_EVM_LOAD_X509=y
|
||||||
CONFIG_SYSTEM_TRUSTED_KEYS=""
|
CONFIG_EVM_X509_PATH="/etc/keys/x509_evm.der"
|
||||||
|
|||||||
Reference in New Issue
Block a user