mirror of
https://github.com/AuxXxilium/linux_dsm_epyc7002.git
synced 2024-12-21 14:38:02 +07:00
7ef84e65ec
The integrity subsystem has lots of options and takes more than half of the security menu. This patch consolidates the options under "integrity", which are hidden if not enabled. This change does not affect existing configurations. Re-configuration is not needed. Changes v4: - no need to change "integrity subsystem" to menuconfig as options are hidden, when not enabled. (Mimi) - add INTEGRITY Kconfig help description Changes v3: - dependency to INTEGRITY removed when behind 'if INTEGRITY' Changes v2: - previous patch moved integrity out of the 'security' menu. This version keeps integrity as a security option (Mimi). Signed-off-by: Dmitry Kasatkin <d.kasatkin@samsung.com> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
45 lines
1.3 KiB
Plaintext
45 lines
1.3 KiB
Plaintext
config EVM
|
|
boolean "EVM support"
|
|
select KEYS
|
|
select ENCRYPTED_KEYS
|
|
select CRYPTO_HMAC
|
|
select CRYPTO_SHA1
|
|
default n
|
|
help
|
|
EVM protects a file's security extended attributes against
|
|
integrity attacks.
|
|
|
|
If you are unsure how to answer this question, answer N.
|
|
|
|
config EVM_ATTR_FSUUID
|
|
bool "FSUUID (version 2)"
|
|
default y
|
|
depends on EVM
|
|
help
|
|
Include filesystem UUID for HMAC calculation.
|
|
|
|
Default value is 'selected', which is former version 2.
|
|
if 'not selected', it is former version 1
|
|
|
|
WARNING: changing the HMAC calculation method or adding
|
|
additional info to the calculation, requires existing EVM
|
|
labeled file systems to be relabeled.
|
|
|
|
config EVM_EXTRA_SMACK_XATTRS
|
|
bool "Additional SMACK xattrs"
|
|
depends on EVM && SECURITY_SMACK
|
|
default n
|
|
help
|
|
Include additional SMACK xattrs for HMAC calculation.
|
|
|
|
In addition to the original security xattrs (eg. security.selinux,
|
|
security.SMACK64, security.capability, and security.ima) included
|
|
in the HMAC calculation, enabling this option includes newly defined
|
|
Smack xattrs: security.SMACK64EXEC, security.SMACK64TRANSMUTE and
|
|
security.SMACK64MMAP.
|
|
|
|
WARNING: changing the HMAC calculation method or adding
|
|
additional info to the calculation, requires existing EVM
|
|
labeled file systems to be relabeled.
|
|
|