aboutsummaryrefslogtreecommitdiffstats
path: root/security/integrity
diff options
context:
space:
mode:
authorRoberto Sassu <roberto.sassu@polito.it>2013-06-07 06:16:35 -0400
committerMimi Zohar <zohar@linux.vnet.ibm.com>2013-10-26 21:32:54 -0400
commit9b9d4ce592d283fc4c01da746c02a840c499bb7e (patch)
treee0778c7a3aef0259a06f03c2f90f271a6789000c /security/integrity
parent4286587dccd43d4f81fa227e413ed7e909895342 (diff)
ima: define kernel parameter 'ima_template=' to change configured default
This patch allows users to specify from the kernel command line the template descriptor, among those defined, that will be used to generate and display measurement entries. If an user specifies a wrong template, IMA reverts to the template descriptor set in the kernel configuration. Signed-off-by: Roberto Sassu <roberto.sassu@polito.it> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Diffstat (limited to 'security/integrity')
-rw-r--r--security/integrity/ima/ima_template.c31
1 files changed, 31 insertions, 0 deletions
diff --git a/security/integrity/ima/ima_template.c b/security/integrity/ima/ima_template.c
index c28ff9bf8f32..000221419f6c 100644
--- a/security/integrity/ima/ima_template.c
+++ b/security/integrity/ima/ima_template.c
@@ -12,6 +12,8 @@
12 * File: ima_template.c 12 * File: ima_template.c
13 * Helpers to manage template descriptors. 13 * Helpers to manage template descriptors.
14 */ 14 */
15#include <crypto/hash_info.h>
16
15#include "ima.h" 17#include "ima.h"
16#include "ima_template_lib.h" 18#include "ima_template_lib.h"
17 19
@@ -32,6 +34,35 @@ static struct ima_template_field supported_fields[] = {
32}; 34};
33 35
34static struct ima_template_desc *ima_template; 36static struct ima_template_desc *ima_template;
37static struct ima_template_desc *lookup_template_desc(const char *name);
38
39static int __init ima_template_setup(char *str)
40{
41 struct ima_template_desc *template_desc;
42 int template_len = strlen(str);
43
44 /*
45 * Verify that a template with the supplied name exists.
46 * If not, use CONFIG_IMA_DEFAULT_TEMPLATE.
47 */
48 template_desc = lookup_template_desc(str);
49 if (!template_desc)
50 return 1;
51
52 /*
53 * Verify whether the current hash algorithm is supported
54 * by the 'ima' template.
55 */
56 if (template_len == 3 && strcmp(str, IMA_TEMPLATE_IMA_NAME) == 0 &&
57 ima_hash_algo != HASH_ALGO_SHA1 && ima_hash_algo != HASH_ALGO_MD5) {
58 pr_err("IMA: template does not support hash alg\n");
59 return 1;
60 }
61
62 ima_template = template_desc;
63 return 1;
64}
65__setup("ima_template=", ima_template_setup);
35 66
36static struct ima_template_desc *lookup_template_desc(const char *name) 67static struct ima_template_desc *lookup_template_desc(const char *name)
37{ 68{