ima: require secure_boot rules in lockdown mode
authorMimi Zohar <zohar@linux.vnet.ibm.com>
Wed, 8 Nov 2017 15:11:32 +0000 (15:11 +0000)
committerBen Hutchings <ben@decadent.org.uk>
Wed, 19 Jun 2019 22:16:58 +0000 (23:16 +0100)
commit53ef5226a0905c4c9659a6984861c223889b4142
treeeb8a57048649ea59d65d8ef0c90c1f33879bbc43
parent6fad688e5516ac3aa6c59f48c665406e56fa46b7
ima: require secure_boot rules in lockdown mode

Require the "secure_boot" rules, whether or not it is specified
on the boot command line, for both the builtin and custom policies
in secure boot lockdown mode.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: David Howells <dhowells@redhat.com>
[bwh: Adjust context to apply after commits 6f0911a666d1
 "ima: fix updating the ima_appraise flag" and ef96837b0de4
 "ima: add build time policy"]

Gbp-Pq: Topic features/all/lockdown
Gbp-Pq: Name 0003-ima-require-secure_boot-rules-in-lockdown-mode.patch
security/integrity/ima/ima_policy.c