Received: by 2002:a25:31c3:0:0:0:0:0 with SMTP id x186csp973067ybx; Wed, 6 Nov 2019 11:11:25 -0800 (PST) X-Google-Smtp-Source: APXvYqyq5B+nw4NPwipJ7t+IKBzQxC+0n4KHr09ZVbmGbTV/mZQcNobhRPp0cgotI7cqyGlbrR1j X-Received: by 2002:a17:906:2ada:: with SMTP id m26mr36517350eje.87.1573067485734; Wed, 06 Nov 2019 11:11:25 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573067485; cv=none; d=google.com; s=arc-20160816; b=YRSVTnQrAI93KP+yUqOaShcDq7RMd8uZuhPrXAF60xjCpPQX2vx0Ux3qt9MWT3vdDw Tj8YDgxbqQO662xunuuRRjXJHobaaprAUMlaWxyJen1cuM9hVvB1ToNmgpnxwPdww8qv VDL1QQc8joBWM8q8ObWSZNtp9AC57bRiqqHhZYzvF6maxpSCmkZPs13/Zq+D5oVx6R5Q eihI7JanE2unoImP7sFmgC7a20TlVFlyOFYfBvvR7xLB/lDle7qnf1VJw5vF0WUork1t t7HNxyoa9w7Nxs52WEY7CM27w0G2zMTN0OdHGQPhw9LDOL4qQMILjQVasYyXREHH0lCj d2dg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:to:from:dkim-signature:dkim-filter; bh=fjc1SDZ6eAyerupfns9th1oRdeR4c1j0/l98r7qhoWI=; b=F3BZXHNIaULC4CjQn4i0Mav4iGM9wZom+qcupE0/lPWogCVLd2Zqod0lbq2L3Ckajt LZWHb76GzY6sYEQCRx55fS7of6Vk/KoaDx4k/cLNTaniJT1ZMxZEfuXFN6BJTh0Q81RC qF70G82uU2ZACoLFFliX1/4PZ5x1IknO4XQIo7gBL6m3BIw6tHoTmWX+v5m/JrH9FcvM lzejbyevXTRiKsd4GVyZYzUAyQBXE7SUugQyGCc+s0qVRl2TSSLgdCv4ziz3N7DtUdb3 xuboJ9F+iHFiuCko3DRl8789vyiWTyrGCB7EBUVjuR/g30VQSTuM/+vuv7lkZNOMtt4Z Jetg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linux.microsoft.com header.s=default header.b=IYQfPpBx; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id os28si3900641ejb.53.2019.11.06.11.11.01; Wed, 06 Nov 2019 11:11:25 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@linux.microsoft.com header.s=default header.b=IYQfPpBx; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732263AbfKFTB1 (ORCPT + 99 others); Wed, 6 Nov 2019 14:01:27 -0500 Received: from linux.microsoft.com ([13.77.154.182]:36128 "EHLO linux.microsoft.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1732215AbfKFTB1 (ORCPT ); Wed, 6 Nov 2019 14:01:27 -0500 Received: from nramas-ThinkStation-P520.corp.microsoft.com (unknown [131.107.174.108]) by linux.microsoft.com (Postfix) with ESMTPSA id 7E2A82010C18; Wed, 6 Nov 2019 11:01:26 -0800 (PST) DKIM-Filter: OpenDKIM Filter v2.11.0 linux.microsoft.com 7E2A82010C18 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.microsoft.com; s=default; t=1573066886; bh=fjc1SDZ6eAyerupfns9th1oRdeR4c1j0/l98r7qhoWI=; h=From:To:Subject:Date:In-Reply-To:References:From; b=IYQfPpBxfFCmXMbhSh7x03hOIBgGLnV2WV8Bb94KUj/gJab9+0p32BILkWBdNZscL u44Maavjs7FLkS3j7zTfE0wnqbT15F5seP9GmE7MnDZPfbb3fIRGOFN0tOQU9OgS/N JMsRdnR1UP3OdLm5I6Rz2OrlUbZKGLHKpB3k0DEc= From: Lakshmi Ramasubramanian To: zohar@linux.ibm.com, dhowells@redhat.com, matthewgarrett@google.com, sashal@kernel.org, jamorris@linux.microsoft.com, linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, keyrings@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v4 01/10] IMA: Defined an IMA hook to measure keys on key create or update Date: Wed, 6 Nov 2019 11:01:07 -0800 Message-Id: <20191106190116.2578-2-nramas@linux.microsoft.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20191106190116.2578-1-nramas@linux.microsoft.com> References: <20191106190116.2578-1-nramas@linux.microsoft.com> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Asymmetric keys used for verifying file signatures or certificates are currently not included in the IMA measurement list. This patch defines a new IMA hook namely ima_post_key_create_or_update() to measure asymmetric keys. Signed-off-by: Lakshmi Ramasubramanian --- security/integrity/ima/ima_main.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/security/integrity/ima/ima_main.c b/security/integrity/ima/ima_main.c index d7e987baf127..a0e233afe876 100644 --- a/security/integrity/ima/ima_main.c +++ b/security/integrity/ima/ima_main.c @@ -721,6 +721,22 @@ void ima_kexec_cmdline(const void *buf, int size) KEXEC_CMDLINE, 0); } +/** + * ima_post_key_create_or_update - measure asymmetric keys + * @keyring: keyring to which the key is linked to + * @key: created or updated key + * @flags: key flags + * @create: flag indicating whether the key was created or updated + * + * Keys can only be measured, not appraised. + */ +void ima_post_key_create_or_update(struct key *keyring, struct key *key, + unsigned long flags, bool create) +{ + if ((keyring != NULL) && (key != NULL)) + return; +} + static int __init init_ima(void) { int error; -- 2.17.1