diff options
author | Dmitry Kasatkin <dmitry.kasatkin@intel.com> | 2012-06-08 12:58:49 +0200 |
---|---|---|
committer | Mimi Zohar <zohar@linux.vnet.ibm.com> | 2013-01-22 22:10:31 +0100 |
commit | 0e5a247cb37a97d843ef76d09d5f80deb7893ba3 (patch) | |
tree | 7206abaf6d20e69a89584046ed7dc9970ba2da12 /samples/kdb | |
parent | ima: forbid write access to files with digital signatures (diff) | |
download | linux-0e5a247cb37a97d843ef76d09d5f80deb7893ba3.tar.xz linux-0e5a247cb37a97d843ef76d09d5f80deb7893ba3.zip |
ima: added policy support for 'security.ima' type
The 'security.ima' extended attribute may contain either the file data's
hash or a digital signature. This patch adds support for requiring a
specific extended attribute type. It extends the IMA policy with a new
keyword 'appraise_type=imasig'. (Default is hash.)
Changelog v2:
- Fixed Documentation/ABI/testing/ima_policy option syntax
Changelog v1:
- Differentiate between 'required' vs. 'actual' extended attribute
Signed-off-by: Dmitry Kasatkin <dmitry.kasatkin@intel.com>
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Diffstat (limited to 'samples/kdb')
0 files changed, 0 insertions, 0 deletions