提交 6478286a 编写于 作者: R Roberto Sassu 提交者: Zheng Zengkai

config: add digest list options for arm64 and x86

hulk inclusion
category: feature
feature: IMA Digest Lists extension
bugzilla: 46797

---------------------------

Enable digest lists and PGP keys preload.
Signed-off-by: NRoberto Sassu <roberto.sassu@huawei.com>
Signed-off-by: NYang Yingliang <yangyingliang@huawei.com>
Reviewed-by: NJason Yan <yanaijie@huawei.com>
Signed-off-by: NZheng Zengkai <zhengzengkai@huawei.com>
上级 106accb6
...@@ -6415,6 +6415,9 @@ CONFIG_IMA_TRUSTED_KEYRING=y ...@@ -6415,6 +6415,9 @@ CONFIG_IMA_TRUSTED_KEYRING=y
CONFIG_IMA_LOAD_X509=y CONFIG_IMA_LOAD_X509=y
CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der" CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der"
# CONFIG_IMA_APPRAISE_SIGNED_INIT is not set # CONFIG_IMA_APPRAISE_SIGNED_INIT is not set
CONFIG_IMA_DIGEST_LIST=y
CONFIG_IMA_DIGEST_LISTS_DIR="/etc/ima/digest_lists"
CONFIG_IMA_PARSER_BINARY_PATH="/usr/bin/upload_digest_lists"
CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS=y CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS=y
CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS=y CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS=y
CONFIG_EVM=y CONFIG_EVM=y
...@@ -6667,6 +6670,9 @@ CONFIG_X509_CERTIFICATE_PARSER=y ...@@ -6667,6 +6670,9 @@ CONFIG_X509_CERTIFICATE_PARSER=y
CONFIG_PKCS7_MESSAGE_PARSER=y CONFIG_PKCS7_MESSAGE_PARSER=y
# CONFIG_PKCS7_TEST_KEY is not set # CONFIG_PKCS7_TEST_KEY is not set
CONFIG_SIGNED_PE_FILE_VERIFICATION=y CONFIG_SIGNED_PE_FILE_VERIFICATION=y
CONFIG_PGP_LIBRARY=y
CONFIG_PGP_KEY_PARSER=y
CONFIG_PGP_PRELOAD=y
# #
# Certificates for signature checking # Certificates for signature checking
...@@ -6677,6 +6683,7 @@ CONFIG_SYSTEM_TRUSTED_KEYS="" ...@@ -6677,6 +6683,7 @@ CONFIG_SYSTEM_TRUSTED_KEYS=""
# CONFIG_SYSTEM_EXTRA_CERTIFICATE is not set # CONFIG_SYSTEM_EXTRA_CERTIFICATE is not set
# CONFIG_SECONDARY_TRUSTED_KEYRING is not set # CONFIG_SECONDARY_TRUSTED_KEYRING is not set
# CONFIG_SYSTEM_BLACKLIST_KEYRING is not set # CONFIG_SYSTEM_BLACKLIST_KEYRING is not set
CONFIG_PGP_PRELOAD_PUBLIC_KEYS=y
# end of Certificates for signature checking # end of Certificates for signature checking
CONFIG_BINARY_PRINTF=y CONFIG_BINARY_PRINTF=y
......
...@@ -3536,19 +3536,19 @@ CONFIG_TCG_TPM=y ...@@ -3536,19 +3536,19 @@ CONFIG_TCG_TPM=y
CONFIG_HW_RANDOM_TPM=y CONFIG_HW_RANDOM_TPM=y
CONFIG_TCG_TIS_CORE=y CONFIG_TCG_TIS_CORE=y
CONFIG_TCG_TIS=y CONFIG_TCG_TIS=y
# CONFIG_TCG_TIS_SPI is not set CONFIG_TCG_TIS_SPI=y
CONFIG_TCG_TIS_I2C_ATMEL=m CONFIG_TCG_TIS_I2C_ATMEL=y
CONFIG_TCG_TIS_I2C_INFINEON=m CONFIG_TCG_TIS_I2C_INFINEON=y
CONFIG_TCG_TIS_I2C_NUVOTON=m CONFIG_TCG_TIS_I2C_NUVOTON=y
CONFIG_TCG_NSC=m CONFIG_TCG_NSC=y
CONFIG_TCG_ATMEL=m CONFIG_TCG_ATMEL=y
CONFIG_TCG_INFINEON=m CONFIG_TCG_INFINEON=y
# CONFIG_TCG_XEN is not set # CONFIG_TCG_XEN is not set
CONFIG_TCG_CRB=y CONFIG_TCG_CRB=y
# CONFIG_TCG_VTPM_PROXY is not set # CONFIG_TCG_VTPM_PROXY is not set
CONFIG_TCG_TIS_ST33ZP24=m CONFIG_TCG_TIS_ST33ZP24=y
CONFIG_TCG_TIS_ST33ZP24_I2C=m CONFIG_TCG_TIS_ST33ZP24_I2C=y
# CONFIG_TCG_TIS_ST33ZP24_SPI is not set CONFIG_TCG_TIS_ST33ZP24_SPI=y
CONFIG_TELCLOCK=m CONFIG_TELCLOCK=m
# CONFIG_XILLYBUS is not set # CONFIG_XILLYBUS is not set
# end of Character devices # end of Character devices
...@@ -7779,6 +7779,9 @@ CONFIG_IMA_TRUSTED_KEYRING=y ...@@ -7779,6 +7779,9 @@ CONFIG_IMA_TRUSTED_KEYRING=y
CONFIG_IMA_LOAD_X509=y CONFIG_IMA_LOAD_X509=y
CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der" CONFIG_IMA_X509_PATH="/etc/keys/x509_ima.der"
# CONFIG_IMA_APPRAISE_SIGNED_INIT is not set # CONFIG_IMA_APPRAISE_SIGNED_INIT is not set
CONFIG_IMA_DIGEST_LIST=y
CONFIG_IMA_DIGEST_LISTS_DIR="/etc/ima/digest_lists"
CONFIG_IMA_PARSER_BINARY_PATH="/usr/bin/upload_digest_lists"
CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS=y CONFIG_IMA_MEASURE_ASYMMETRIC_KEYS=y
CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS=y CONFIG_IMA_QUEUE_EARLY_BOOT_KEYS=y
# CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set # CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set
...@@ -8061,6 +8064,9 @@ CONFIG_X509_CERTIFICATE_PARSER=y ...@@ -8061,6 +8064,9 @@ CONFIG_X509_CERTIFICATE_PARSER=y
CONFIG_PKCS7_MESSAGE_PARSER=y CONFIG_PKCS7_MESSAGE_PARSER=y
# CONFIG_PKCS7_TEST_KEY is not set # CONFIG_PKCS7_TEST_KEY is not set
CONFIG_SIGNED_PE_FILE_VERIFICATION=y CONFIG_SIGNED_PE_FILE_VERIFICATION=y
CONFIG_PGP_LIBRARY=y
CONFIG_PGP_KEY_PARSER=y
CONFIG_PGP_PRELOAD=y
# #
# Certificates for signature checking # Certificates for signature checking
...@@ -8072,6 +8078,7 @@ CONFIG_SYSTEM_TRUSTED_KEYS="" ...@@ -8072,6 +8078,7 @@ CONFIG_SYSTEM_TRUSTED_KEYS=""
# CONFIG_SECONDARY_TRUSTED_KEYRING is not set # CONFIG_SECONDARY_TRUSTED_KEYRING is not set
CONFIG_SYSTEM_BLACKLIST_KEYRING=y CONFIG_SYSTEM_BLACKLIST_KEYRING=y
CONFIG_SYSTEM_BLACKLIST_HASH_LIST="" CONFIG_SYSTEM_BLACKLIST_HASH_LIST=""
CONFIG_PGP_PRELOAD_PUBLIC_KEYS=y
# end of Certificates for signature checking # end of Certificates for signature checking
CONFIG_BINARY_PRINTF=y CONFIG_BINARY_PRINTF=y
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册