|
@@ -34,9 +34,10 @@ Description:
|
|
fsuuid:= file system UUID (e.g 8bcbe394-4f13-4144-be8e-5aa9ea2ce2f6)
|
|
fsuuid:= file system UUID (e.g 8bcbe394-4f13-4144-be8e-5aa9ea2ce2f6)
|
|
uid:= decimal value
|
|
uid:= decimal value
|
|
euid:= decimal value
|
|
euid:= decimal value
|
|
- fowner:=decimal value
|
|
|
|
|
|
+ fowner:= decimal value
|
|
lsm: are LSM specific
|
|
lsm: are LSM specific
|
|
option: appraise_type:= [imasig]
|
|
option: appraise_type:= [imasig]
|
|
|
|
+ pcr:= decimal value
|
|
|
|
|
|
default policy:
|
|
default policy:
|
|
# PROC_SUPER_MAGIC
|
|
# PROC_SUPER_MAGIC
|
|
@@ -96,3 +97,8 @@ Description:
|
|
|
|
|
|
Smack:
|
|
Smack:
|
|
measure subj_user=_ func=FILE_CHECK mask=MAY_READ
|
|
measure subj_user=_ func=FILE_CHECK mask=MAY_READ
|
|
|
|
+
|
|
|
|
+ Example of measure rules using alternate PCRs:
|
|
|
|
+
|
|
|
|
+ measure func=KEXEC_KERNEL_CHECK pcr=4
|
|
|
|
+ measure func=KEXEC_INITRAMFS_CHECK pcr=5
|