ima: based on policy require signed kexec kernel images
The original kexec_load syscall can not verify file signatures, nor can the kexec image be measured. Based on policy, deny the kexec_load syscall. Signed-off-by:Mimi Zohar <zohar@linux.vnet.ibm.com> Cc: Eric Biederman <ebiederm@xmission.com> Cc: Kees Cook <keescook@chromium.org> Reviewed-by:
Kees Cook <keescook@chromium.org> Signed-off-by:
James Morris <james.morris@microsoft.com>
Showing
- include/linux/ima.h 7 additions, 0 deletionsinclude/linux/ima.h
- security/integrity/ima/ima.h 1 addition, 0 deletionssecurity/integrity/ima/ima.h
- security/integrity/ima/ima_main.c 27 additions, 0 deletionssecurity/integrity/ima/ima_main.c
- security/integrity/ima/ima_policy.c 2 additions, 0 deletionssecurity/integrity/ima/ima_policy.c
- security/security.c 6 additions, 1 deletionsecurity/security.c
Please register or sign in to comment