ima.cfg: update to 5.0 kernel

Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
Armin Kuster
2019-05-19 09:51:08 -07:00
parent 756a1649b7
commit f26869aef3
2 changed files with 18 additions and 16 deletions

View File

@@ -1,16 +1,18 @@
# Enable bare minimum IMA measurement and appraisal as needed by this layer.
CONFIG_SECURITY=y
CONFIG_INTEGRITY=y
# measurement
CONFIG_IMA=y
# appraisal
CONFIG_IMA_MEASURE_PCR_IDX=10
CONFIG_IMA_NG_TEMPLATE=y
CONFIG_IMA_DEFAULT_TEMPLATE="ima-ng"
CONFIG_IMA_DEFAULT_HASH_SHA1=y
CONFIG_IMA_DEFAULT_HASH="sha1"
CONFIG_IMA_APPRAISE=y
CONFIG_INTEGRITY_SIGNATURE=y
CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
# Kernel will get built with embedded X.509 root CA key and all keys
# need to be signed with that.
CONFIG_IMA_APPRAISE_BOOTPARAM=y
CONFIG_IMA_TRUSTED_KEYRING=y
CONFIG_SIGNATURE=y
CONFIG_IMA_WRITE_POLICY=y
CONFIG_IMA_READ_POLICY=y
CONFIG_IMA_LOAD_X509=y
CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der"
#CONFIG_INTEGRITY_SIGNATURE=y
#CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
#CONFIG_INTEGRITY_TRUSTED_KEYRING=y

View File

@@ -1,3 +1,3 @@
CONFIG_KEYS=y
CONFIG_SYSTEM_TRUSTED_KEYRING=y
CONFIG_SYSTEM_TRUSTED_KEYS=""
# CONFIG_IMA_APPRAISE_SIGNED_INIT is not set
CONFIG_EVM_LOAD_X509=y
CONFIG_EVM_X509_PATH="/etc/keys/x509_evm.der"