Stefan Berger
|
2afd020aae
ima: Do not audit if CONFIG_INTEGRITY_AUDIT is not set
|
7 years ago |
Matthew Garrett
|
0c343af806
integrity: Add an integrity directory in securityfs
|
7 years ago |
Thiago Jung Bauermann
|
11c60f23ed
integrity: Remove unused macro IMA_ACTION_RULE_FLAGS
|
7 years ago |
Mimi Zohar
|
9e67028e76
ima: fail signature verification based on policy
|
7 years ago |
Matthew Garrett
|
d906c10d8a
IMA: Support using new creds in appraisal policy
|
7 years ago |
Mimi Zohar
|
da1b0029f5
ima: support new "hash" and "dont_hash" policy actions
|
8 years ago |
Dmitry Kasatkin
|
0d73a55208
ima: re-introduce own integrity cache lock
|
7 years ago |
Matthew Garrett
|
50b977481f
EVM: Add support for portable signature format
|
7 years ago |
Christoph Hellwig
|
a7d3d0392a
integrity: use kernel_read_file_from_path() to read x509 certs
|
8 years ago |
Thiago Jung Bauermann
|
bb543e3959
integrity: Small code improvements
|
8 years ago |
Eric Richter
|
96d450bbec
integrity: add measured_pcrs field to integrity cache
|
9 years ago |
Mimi Zohar
|
42a4c60319
ima: fix ima_inode_post_setattr
|
9 years ago |
James Morris
|
88a1b564a2
Merge tag 'keys-next-20160303' of git://git.kernel.org/pub/scm/linux/kernel/git/dhowells/linux-fs into next
|
9 years ago |
David Howells
|
4e8ae72a75
X.509: Make algo identifiers text instead of enum
|
9 years ago |
Mimi Zohar
|
c6af8efe97
ima: remove firmware and module specific cached status info
|
9 years ago |
Mimi Zohar
|
cf22221786
ima: define a new hook to measure and appraise a file already in memory
|
9 years ago |
Dmitry Kasatkin
|
2ce523eb89
evm: load an x509 certificate from the kernel
|
9 years ago |
Dmitry Kasatkin
|
f4dc37785e
integrity: define '.evm' as a builtin 'trusted' keyring
|
9 years ago |
Dmitry Kasatkin
|
9d03a721a3
integrity: add validity checks for 'path' parameter
|
10 years ago |
Linus Torvalds
|
67e2c38838
Merge branch 'next' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
|
10 years ago |
Dmitry Kasatkin
|
fd5f4e9054
ima: load x509 certificate from the kernel
|
10 years ago |
Dmitry Kasatkin
|
65d543b233
integrity: provide a function to load x509 certificate from the kernel
|
10 years ago |
Dmitry Kasatkin
|
e3c4abbfa9
integrity: define a new function integrity_read_file()
|
10 years ago |
Dmitry Kasatkin
|
a48fda9de9
ima: check xattr value length and type in the ima_inode_setxattr()
|
10 years ago |
Dmitry Kasatkin
|
d16a8585d3
integrity: add missing '__init' keyword for integrity_init_keyring()
|
11 years ago |
Dmitry Kasatkin
|
0f34a0060a
ima: check ima_policy_flag in the ima_file_free() hook
|
11 years ago |
Dmitry Kasatkin
|
65d98f3be2
integrity: remove declaration of non-existing functions
|
11 years ago |
Dmitry Kasatkin
|
b151d6b00b
ima: provide flag to identify new empty files
|
11 years ago |
Mimi Zohar
|
5a9196d715
ima: add support for measuring and appraising firmware
|
11 years ago |
Mimi Zohar
|
7d2ce2320e
ima: define '.ima' as a builtin 'trusted' keyring
|
12 years ago |