ipe: add support for dm-verity as a trust provider
Allows author of IPE policy to indicate trust for a singular dm-verity volume, identified by roothash, through "dmverity_roothash" and all signed and validated dm-verity volumes, through "dmverity_signature". Signed-off-by:Deven Bowers <deven.desai@linux.microsoft.com> Signed-off-by:
Fan Wu <wufan@linux.microsoft.com> [PM: fixed some line length issues in the comments] Signed-off-by:
Paul Moore <paul@paul-moore.com>
Showing
- security/ipe/Kconfig 27 additions, 0 deletionssecurity/ipe/Kconfig
- security/ipe/Makefile 1 addition, 0 deletionssecurity/ipe/Makefile
- security/ipe/audit.c 27 additions, 2 deletionssecurity/ipe/audit.c
- security/ipe/digest.c 118 additions, 0 deletionssecurity/ipe/digest.c
- security/ipe/digest.h 26 additions, 0 deletionssecurity/ipe/digest.h
- security/ipe/eval.c 92 additions, 1 deletionsecurity/ipe/eval.c
- security/ipe/eval.h 12 additions, 0 deletionssecurity/ipe/eval.h
- security/ipe/hooks.c 92 additions, 0 deletionssecurity/ipe/hooks.c
- security/ipe/hooks.h 8 additions, 0 deletionssecurity/ipe/hooks.h
- security/ipe/ipe.c 15 additions, 0 deletionssecurity/ipe/ipe.c
- security/ipe/ipe.h 4 additions, 0 deletionssecurity/ipe/ipe.h
- security/ipe/policy.h 3 additions, 0 deletionssecurity/ipe/policy.h
- security/ipe/policy_parser.c 23 additions, 1 deletionsecurity/ipe/policy_parser.c
- security/security.c 12 additions, 11 deletionssecurity/security.c
Loading
Please register or sign in to comment