mirror of
https://github.com/AuxXxilium/linux_dsm_epyc7002.git
synced 2024-12-26 23:15:24 +07:00
a802ed0dd9
The kernel CONFIG_KEXEC_VERIFY_SIG option is limited to verifying a kernel image's signature, when loaded via the kexec_file_load syscall. There is no method for verifying a kernel image's signature loaded via the kexec_load syscall. This test verifies loading the kernel image via the kexec_load syscall fails when the kernel CONFIG_KEXEC_VERIFY_SIG option is enabled on systems with secureboot enabled[1]. [1] Detecting secureboot enabled is architecture specific. Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
5 lines
85 B
Plaintext
5 lines
85 B
Plaintext
CONFIG_IMA_APPRAISE
|
|
CONFIG_IMA_ARCH_POLICY
|
|
CONFIG_SECURITYFS
|
|
CONFIG_KEXEC_VERIFY_SIG
|