ima: require secure_boot rules in lockdown mode
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Wed, 8 Nov 2017 15:11:32 +0000 (15:11 +0000)
committerBen Hutchings <ben@decadent.org.uk>
Fri, 15 Mar 2019 02:16:04 +0000 (02:16 +0000)
commit3f62368a96ac462c5067ea15105509c624db1f4b
treecaf5806553e32c306d3a86c8d3550fdb3729e001
parent0a2404a6900606448e664bcfd12c6f0c4dba9e4d
ima: require secure_boot rules in lockdown mode

Require the "secure_boot" rules, whether or not it is specified
on the boot command line, for both the builtin and custom policies
in secure boot lockdown mode.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: David Howells <dhowells@redhat.com>
[bwh: Adjust context to apply after commits 6f0911a666d1
 "ima: fix updating the ima_appraise flag" and ef96837b0de4
 "ima: add build time policy"]

Gbp-Pq: Topic features/all/lockdown
Gbp-Pq: Name 0003-ima-require-secure_boot-rules-in-lockdown-mode.patch
security/integrity/ima/ima_policy.c