From: Nayna <nayna@linux.vnet.ibm.com>
To: Bruno Meneguele <bmeneg@redhat.com>
Cc: linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org,
zohar@linux.ibm.com, erichte@linux.ibm.com, nayna@linux.ibm.com,
stable@vger.kernel.org
Subject: Re: [PATCH v2] ima: move APPRAISE_BOOTPARAM dependency on ARCH_POLICY to runtime
Date: Mon, 22 Jun 2020 15:01:27 -0400 [thread overview]
Message-ID: <043e52d4-6835-c2c4-bc9d-d36ddb3db0e9@linux.vnet.ibm.com> (raw)
In-Reply-To: <20200622172754.10763-1-bmeneg@redhat.com>
On 6/22/20 1:27 PM, Bruno Meneguele wrote:
> IMA_APPRAISE_BOOTPARAM has been marked as dependent on !IMA_ARCH_POLICY in
> compile time, enforcing the appraisal whenever the kernel had the arch
> policy option enabled.
>
> However it breaks systems where the option is actually set but the system
> wasn't booted in a "secure boot" platform. In this scenario, anytime the
> an appraisal policy (i.e. ima_policy=appraisal_tcb) is used it will be
> forced, giving no chance to the user set the 'fix' state (ima_appraise=fix)
> to actually measure system's files.
>
> This patch remove this compile time dependency and move it to a runtime
> decision, based on the arch policy loading failure/success.
Thanks for looking at this.
For arch specific policies, kernel signature verification is enabled
based on the secure boot state of the system. Perhaps, enforce the
appraisal as well based on if secure boot is enabled.
Thanks & Regards,
- Nayna
next prev parent reply other threads:[~2020-06-22 19:01 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-06-22 17:27 Bruno Meneguele
2020-06-22 19:01 ` Nayna [this message]
2020-06-22 19:21 ` Bruno Meneguele
2020-06-22 19:28 ` Mimi Zohar
2020-06-22 20:16 ` Bruno Meneguele
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=043e52d4-6835-c2c4-bc9d-d36ddb3db0e9@linux.vnet.ibm.com \
--to=nayna@linux.vnet.ibm.com \
--cc=bmeneg@redhat.com \
--cc=erichte@linux.ibm.com \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nayna@linux.ibm.com \
--cc=stable@vger.kernel.org \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®