summaryrefslogtreecommitdiffstats
path: root/init/version.c
diff options
context:
space:
mode:
authorEric Biggers <ebiggers@google.com>2019-07-22 18:26:23 +0200
committerEric Biggers <ebiggers@google.com>2019-08-13 04:33:50 +0200
commit432434c9f8e18cb4cf0fe05bc3eeceada0e10dc6 (patch)
treecfcf57b2bb1fbdb1e9b5739f020b0311405363c0 /init/version.c
parentfs-verity: add SHA-512 support (diff)
downloadlinux-432434c9f8e18cb4cf0fe05bc3eeceada0e10dc6.tar.xz
linux-432434c9f8e18cb4cf0fe05bc3eeceada0e10dc6.zip
fs-verity: support builtin file signatures
To meet some users' needs, add optional support for having fs-verity handle a portion of the authentication policy in the kernel. An ".fs-verity" keyring is created to which X.509 certificates can be added; then a sysctl 'fs.verity.require_signatures' can be set to cause the kernel to enforce that all fs-verity files contain a signature of their file measurement by a key in this keyring. See the "Built-in signature verification" section of Documentation/filesystems/fsverity.rst for the full documentation. Reviewed-by: Theodore Ts'o <tytso@mit.edu> Signed-off-by: Eric Biggers <ebiggers@google.com>
Diffstat (limited to 'init/version.c')
0 files changed, 0 insertions, 0 deletions