• Mickaël Salaün's avatar
    dm verity: Add support for signature verification with 2nd keyring · 4da8f8c8
    Mickaël Salaün authored
    Add a new configuration DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING
    to enable dm-verity signatures to be verified against the secondary
    trusted keyring.  Instead of relying on the builtin trusted keyring
    (with hard-coded certificates), the second trusted keyring can include
    certificate authorities from the builtin trusted keyring and child
    certificates loaded at run time.  Using the secondary trusted keyring
    enables to use dm-verity disks (e.g. loop devices) signed by keys which
    did not exist at kernel build time, leveraging the certificate chain of
    trust model.  In practice, this makes it possible to update certificates
    without kernel update and reboot, aligning with module and kernel
    (kexec) signature verification which already use the secondary trusted
    keyring.
    Signed-off-by: default avatarMickaël Salaün <mic@linux.microsoft.com>
    Signed-off-by: default avatarMike Snitzer <snitzer@redhat.com>
    4da8f8c8
dm-verity-verify-sig.c 3.12 KB