mirror of
https://git.yoctoproject.org/meta-security
synced 2026-06-04 14:10:22 +00:00
linux: add support for kernel modules signing
Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>
This commit is contained in:
committed by
Armin Kuster
parent
79bc2559fe
commit
eebe0ff18a
@@ -1,3 +1,6 @@
|
||||
FILESEXTRAPATHS_prepend := "${THISDIR}/linux:"
|
||||
|
||||
SRC_URI += "${@bb.utils.contains('DISTRO_FEATURES', 'ima', ' file://ima.cfg', '', d)}"
|
||||
SRC_URI += "${@bb.utils.contains('DISTRO_FEATURES', 'modsign', ' file://modsign.scc file://modsign.cfg', '', d)}"
|
||||
|
||||
inherit ${@bb.utils.contains('DISTRO_FEATURES', 'modsign', 'kernel-modsign', '', d)}
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
CONFIG_MODULE_SIG=y
|
||||
CONFIG_MODULE_SIG_FORCE=y
|
||||
CONFIG_MODULE_SIG_SHA256=y
|
||||
CONFIG_MODULE_SIG_HASH="sha256"
|
||||
CONFIG_MODULE_SIG_KEY="modsign_key.pem"
|
||||
@@ -0,0 +1,4 @@
|
||||
define KFEATURE_DESCRIPTION "Kernel Module Signing (modsign) enablement"
|
||||
define KFEATURE_COMPATIBILITY all
|
||||
|
||||
kconf non-hardware modsign.cfg
|
||||
Reference in New Issue
Block a user