diff options
author | David Howells <dhowells@redhat.com> | 2015-07-20 16:16:27 -0400 |
---|---|---|
committer | David Howells <dhowells@redhat.com> | 2015-08-07 11:26:13 -0400 |
commit | 3f1e1bea34740069f70c6bc92d0f712345d5c28e (patch) | |
tree | 35ceac092ff7591536810cceecdbf22f4132b046 /init | |
parent | bc1c373dd2a5113800360f7152be729c9da996cc (diff) |
MODSIGN: Use PKCS#7 messages as module signatures
Move to using PKCS#7 messages as module signatures because:
(1) We have to be able to support the use of X.509 certificates that don't
have a subjKeyId set. We're currently relying on this to look up the
X.509 certificate in the trusted keyring list.
(2) PKCS#7 message signed information blocks have a field that supplies the
data required to match with the X.509 certificate that signed it.
(3) The PKCS#7 certificate carries fields that specify the digest algorithm
used to generate the signature in a standardised way and the X.509
certificates specify the public key algorithm in a standardised way - so
we don't need our own methods of specifying these.
(4) We now have PKCS#7 message support in the kernel for signed kexec purposes
and we can make use of this.
To make this work, the old sign-file script has been replaced with a program
that needs compiling in a previous patch. The rules to build it are added
here.
Signed-off-by: David Howells <dhowells@redhat.com>
Tested-by: Vivek Goyal <vgoyal@redhat.com>
Diffstat (limited to 'init')
-rw-r--r-- | init/Kconfig | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/init/Kconfig b/init/Kconfig index af09b4fb43d2..e16d9e587cee 100644 --- a/init/Kconfig +++ b/init/Kconfig | |||
@@ -1869,6 +1869,7 @@ config MODULE_SIG | |||
1869 | select ASN1 | 1869 | select ASN1 |
1870 | select OID_REGISTRY | 1870 | select OID_REGISTRY |
1871 | select X509_CERTIFICATE_PARSER | 1871 | select X509_CERTIFICATE_PARSER |
1872 | select PKCS7_MESSAGE_PARSER | ||
1872 | help | 1873 | help |
1873 | Check modules for valid signatures upon load: the signature | 1874 | Check modules for valid signatures upon load: the signature |
1874 | is simply appended to the module. For more information see | 1875 | is simply appended to the module. For more information see |