• D
    KEYS: validate certificate trust only with builtin keys · 32c4741c
    Dmitry Kasatkin 提交于
    Instead of allowing public keys, with certificates signed by any
    key on the system trusted keyring, to be added to a trusted keyring,
    this patch further restricts the certificates to those signed only by
    builtin keys on the system keyring.
    
    This patch defines a new option 'builtin' for the kernel parameter
    'keys_ownerid' to allow trust validation using builtin keys.
    
    Simplified Mimi's "KEYS: define an owner trusted keyring" patch
    
    Changelog v7:
    - rename builtin_keys to use_builtin_keys
    Signed-off-by: NDmitry Kasatkin <d.kasatkin@samsung.com>
    Signed-off-by: NMimi Zohar <zohar@linux.vnet.ibm.com>
    32c4741c
key.h 11.0 KB