mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 0/3][RESEND] modsign enhancement
@ 2018-03-24  2:59 Jia Zhang
  2018-03-24  2:59 ` [PATCH 1/3] module: Do not access sig_enforce directly Jia Zhang
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Jia Zhang @ 2018-03-24  2:59 UTC (permalink / raw)
  To: jeyu; +Cc: linux-kernel, zhang.jia

This patch series allows to disable module validity enforcement
in runtime through the control switch located in securityfs.

In order to keep /sys/module/module/parameters/sig_enforce simple,
the disablement switch is located at
/sys/kernel/security/modsign/disable_enforce.

Assuming CONFIG_MODULE_SIG_FORCE=n, here are the instructions to
test this control switch.

# cat /sys/module/module/parameters/sig_enforce
N
# echo 1 > /sys/module/module/parameters/sig_enforce
# cat /sys/module/module/parameters/sig_enforce
Y
# echo -n 0 > no_sig_enforce
# openssl smime -sign -nocerts -noattr -binary -in no_sig_enforce \
    -inkey <system_trusted_key> -signer <cert> -outform der \
    -out /sys/kernel/security/modsign/disable_enforce
# cat /sys/module/module/parameters/sig_enforce
N

Changelog:
v3:
- The control switch now doesn't support showing the status of sig_enforce.

v2:
- Support to disable validity enforcement in runtime.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2018-03-28  1:02 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-03-24  2:59 [PATCH v3 0/3][RESEND] modsign enhancement Jia Zhang
2018-03-24  2:59 ` [PATCH 1/3] module: Do not access sig_enforce directly Jia Zhang
2018-03-24  2:59 ` [PATCH 2/3] module: Create the entry point initialize_module() Jia Zhang
2018-03-24  2:59 ` [PATCH 3/3] module: Support to disable validity enforcement in runtime Jia Zhang
2018-03-27 22:11 ` [PATCH v3 0/3][RESEND] modsign enhancement Jessica Yu
2018-03-28  1:02   ` Jia Zhang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®