mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Luis R. Rodriguez" <mcgrof@suse.com>
To: Paul Moore <paul@paul-moore.com>
Cc: "Roberts, William C" <william.c.roberts@intel.com>,
	"David Woodhouse" <dwmw2@infradead.org>,
	"David Howells" <dhowells@redhat.com>,
	"Mimi Zohar" <zohar@linux.vnet.ibm.com>,
	"Andy Lutomirski" <luto@amacapital.net>,
	"Kees Cook" <keescook@chromium.org>,
	"linux-security-module@vger.kernel.org"
	<linux-security-module@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"linux-wireless@vger.kernel.org" <linux-wireless@vger.kernel.org>,
	"james.l.morris@oracle.com" <james.l.morris@oracle.com>,
	"serge@hallyn.com" <serge@hallyn.com>,
	"Vitaly Kuznetsov" <vkuznets@redhat.com>,
	"Eric Paris" <eparis@parisplace.org>,
	"selinux@tycho.nsa.gov" <selinux@tycho.nsa.gov>,
	"Stephen Smalley" <sds@tycho.nsa.gov>,
	"Schaufler, Casey" <casey.schaufler@intel.com>,
	"Luis R. Rodriguez" <mcgrof@do-not-panic.com>,
	"Dmitry Kasatkin" <dmitry.kasatkin@gmail.com>,
	"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Peter Jones" <pjones@redhat.com>, "Takashi Iwai" <tiwai@suse.de>,
	"Ming Lei" <ming.lei@canonical.com>, "Joey Lee" <jlee@suse.de>,
	"Vojtech Pavlík" <vojtech@suse.com>,
	"Kyle McMartin" <kyle@kernel.org>,
	"Seth Forshee" <seth.forshee@canonical.com>,
	"Matthew Garrett" <mjg59@srcf.ucam.org>,
	"Johannes Berg" <johannes@sipsolutions.net>
Subject: Re: Linux Firmware Signing
Date: Sat, 29 Aug 2015 04:03:01 +0200	[thread overview]
Message-ID: <20150829020301.GM8051@wotan.suse.de> (raw)
In-Reply-To: <CAHC9VhRF-39ZbwawkM-aR+th2nRPEVF9-nR1NEHDPDmakpt4FQ@mail.gmail.com>

On Fri, Aug 28, 2015 at 06:26:05PM -0400, Paul Moore wrote:
> On Fri, Aug 28, 2015 at 7:20 AM, Roberts, William C
> <william.c.roberts@intel.com> wrote:
> > Even triggered updates make sense, since you can at least have some form of trust
> > of where that binary policy came from.
> 
> It isn't always that simple, see my earlier comments about
> customization and manipulation by the policy loading tools.

If the customization of the data is done in kernel then the kernel
can *first* verify the file's signature prior to doing any data
modification. If userspace does the modification then the signature
stuff won't work unless the tool will have access to the MOK and can
sign it pre-flight to the kernel selinuxfs.

> > Huh, not following? Perhaps, I am not following what your laying down here.
> >
> >  Right now there is no signing on the selinux policy file. We should be able
> > to just use the firmware signing api's as is (I have not looked on linux-next yet)
> > to unpack the blob.
> 
> I haven't looked at the existing fw signing hook in any detail to be
> able to comment on its use as a policy verification hook.  As long as
> we preserve backwards compatibility and don't introduce a new
> mechanism/API for loading SELinux policy I doubt I would have any
> objections.

You'd just have to implement a permissive model as we are with the
fw signing. No radical customizations, except one thing to note is
that on the fw signing side of things we're going to have the signature
of the file *detached* in separate file. I think what you're alluding
to is the issue of where that signature would be stuff in the SELinux
policy file and its correct that you'd need to address that. You could
just borrow the kernel's model and reader / sucker that strips out the
signature. Another possibility would be two files but then I guess
you'd need a trigger to annotate both are in place.

  Luis

  reply	other threads:[~2015-08-29  2:03 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20150824210234.GI8051@wotan.suse.de>
     [not found] ` <476DC76E7D1DF2438D32BFADF679FC5601057D32@ORSMSX103.amr.corp.intel.com>
     [not found]   ` <20150824225713.GJ8051@wotan.suse.de>
     [not found]     ` <CAGXu5jLDHCgygaVNHpuvszN6SXNKAjRW83q3-D2ZfRpO4uAmdw@mail.gmail.com>
     [not found]       ` <476DC76E7D1DF2438D32BFADF679FC5601058E78@ORSMSX103.amr.corp.intel.com>
     [not found]         ` <CAGXu5jJuwPfnQhu9u4-90UkmjWTBF_GLpJ7J1VaaT2D0d_-Mhg@mail.gmail.com>
     [not found]           ` <1440462367.2737.4.camel@linux.vnet.ibm.com>
     [not found]             ` <CALCETrXWBBdOKz-fSdM7YVu_sWQbA3YsHPeZAkRmtj+eawqZGQ@mail.gmail.com>
     [not found]               ` <1440464705.2737.36.camel@linux.vnet.ibm.com>
     [not found]                 ` <14540.1440599584@warthog.procyon.org.uk>
2015-08-26 23:26                   ` Luis R. Rodriguez
2015-08-27  2:35                     ` Paul Moore
2015-08-27 19:36                       ` Luis R. Rodriguez
2015-08-27 23:46                         ` Paul Moore
2015-08-27 10:38                   ` David Howells
2015-08-27 10:57                     ` David Woodhouse
2015-08-27 21:29                       ` Luis R. Rodriguez
2015-08-27 23:54                         ` Mimi Zohar
2015-08-29  2:16                           ` Luis R. Rodriguez
2015-08-31 14:18                             ` Mimi Zohar
2015-08-31 16:05                               ` David Woodhouse
2015-08-31 16:45                                 ` Mimi Zohar
2015-09-02  0:00                                   ` Luis R. Rodriguez
2015-09-01 23:43                               ` Luis R. Rodriguez
2015-09-02  3:08                                 ` Kees Cook
2015-09-02  3:44                                   ` Mimi Zohar
2015-09-02 15:28                                     ` Kees Cook
2015-09-02 16:45                                       ` Mimi Zohar
2015-09-02 17:36                                         ` Austin S Hemmelgarn
2015-09-02 23:54                                 ` Mimi Zohar
2015-09-03  0:18                                   ` Luis R. Rodriguez
2015-08-27 23:56                         ` Paul Moore
2015-08-28 11:20                           ` Roberts, William C
2015-08-28 22:26                             ` Paul Moore
2015-08-29  2:03                               ` Luis R. Rodriguez [this message]
2015-09-01  2:52                                 ` Paul Moore
2015-09-01 14:12                                   ` Joshua Brindle
2015-09-01 20:08                                     ` Roberts, William C
2015-09-01 20:46                                       ` Joshua Brindle
2015-09-01 22:21                                   ` Eric Paris
2015-08-29  1:56                             ` Luis R. Rodriguez
2015-09-01 20:20                         ` Kees Cook
2015-09-02  0:09                           ` Luis R. Rodriguez
2015-09-02  3:35                             ` Mimi Zohar
2015-09-02 18:46                               ` Luis R. Rodriguez
2015-09-02 20:54                                 ` Kees Cook
2015-09-02 21:37                                   ` Luis R. Rodriguez
2015-09-03 21:14                                     ` Kees Cook
2015-09-30 20:34                                       ` Luis R. Rodriguez
2015-09-03  0:05                                 ` Mimi Zohar
2015-09-03  0:29                                   ` Luis R. Rodriguez
2015-09-03  3:00                                     ` Mimi Zohar
2015-08-27 19:37                     ` Luis R. Rodriguez

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20150829020301.GM8051@wotan.suse.de \
    --to=mcgrof@suse.com \
    --cc=casey.schaufler@intel.com \
    --cc=dhowells@redhat.com \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=dwmw2@infradead.org \
    --cc=eparis@parisplace.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=james.l.morris@oracle.com \
    --cc=jlee@suse.de \
    --cc=johannes@sipsolutions.net \
    --cc=keescook@chromium.org \
    --cc=kyle@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=luto@amacapital.net \
    --cc=mcgrof@do-not-panic.com \
    --cc=ming.lei@canonical.com \
    --cc=mjg59@srcf.ucam.org \
    --cc=paul@paul-moore.com \
    --cc=pjones@redhat.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    --cc=serge@hallyn.com \
    --cc=seth.forshee@canonical.com \
    --cc=tiwai@suse.de \
    --cc=vkuznets@redhat.com \
    --cc=vojtech@suse.com \
    --cc=william.c.roberts@intel.com \
    --cc=zohar@linux.vnet.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®