Received: by 2002:a05:6a10:6744:0:0:0:0 with SMTP id w4csp4661090pxu; Tue, 13 Oct 2020 04:14:11 -0700 (PDT) X-Google-Smtp-Source: ABdhPJysoaKQz+4wHVqa36r5r5EuF9FPQ6n71UBzrjLdvEtCDu3/d5g0NdRcJlT9eRwHN0gg2oMl X-Received: by 2002:aa7:c442:: with SMTP id n2mr19259208edr.309.1602587651532; Tue, 13 Oct 2020 04:14:11 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1602587651; cv=none; d=google.com; s=arc-20160816; b=Dp5/IJdwahd7H7MeD4B4nGeY3yGWvwMVd5MWpGOOUP2FxilDhCD6uJFJ1fBNIjTU1F d11cMwS3J5zkt3koxFpmjvL7c1tU4/F9tdP8FTcO04Wciz3Fer6DTb4DyeUGcARtKEIy SVBliwfS/yuhIvqHW4qhd8p9+8joL2Uir8Z1BaRg4Q+CIb8yZXSFpnWcSop21zNsXIsK dTcbs290kPBgaOpFx2Sm4ci8eVX6RJX9cjgFN8A8EUlg6qeJ6FCJgYovNfLQhHJIojIe QeiEDLmw/+JD5z+tc5nZqH/PlZHIIXdQqTUaFdOMqn3Gg7ulDoz93B77HbTyb9nN79ys 5Sow== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:organization:in-reply-to :content-transfer-encoding:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:ironport-sdr :ironport-sdr; bh=k1kGDCy2RCenpv1cK5h3Xxwu/OQljcpBeJyhP2CP5YE=; b=BqTWhazwdYzOvoxF6PPHvThM/ub5b6bW39hv7Xy3BjRSS8SqELHctiE7LM3Q1ZJ32Q WtokHywf2y6AMZLoPU4mKzdXzs3vQjZKmp8oei5HNScKeq8xodWTv1HvLSoq/uabmWDq npxyi0SE5tMypchTM+lpCLvvdsv6VG4RRyc8dxQgG2C3BBBRhD8SOGSQxIe7XEgfzudu djPAfTVkNI72HMXj8q5ghft2bOy721ZCa3P8rcSa61U/YmusYE+9kj3sKrJPR03mdNCG 0gEBohpLUUKHjj/H/6WwQp6Az4LUyycjoMr2en+6m58AhxS8vZMlKi/bPDcNEYty/aZ1 5e5Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id h27si836761eje.332.2020.10.13.04.13.49; Tue, 13 Oct 2020 04:14:11 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730968AbgJLXzJ (ORCPT + 99 others); Mon, 12 Oct 2020 19:55:09 -0400 Received: from mga12.intel.com ([192.55.52.136]:20992 "EHLO mga12.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728821AbgJLXzI (ORCPT ); Mon, 12 Oct 2020 19:55:08 -0400 IronPort-SDR: 3GFYgVk+GQCZSlXQDC9h9DdYFMG49IcrwGpnzYoKqTunWJdGqzWakGRFHJTytU2VMzLlwEC8XN bQzEeHYfuZhA== X-IronPort-AV: E=McAfee;i="6000,8403,9772"; a="145139069" X-IronPort-AV: E=Sophos;i="5.77,368,1596524400"; d="scan'208";a="145139069" X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga005.jf.intel.com ([10.7.209.41]) by fmsmga106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 12 Oct 2020 16:55:07 -0700 IronPort-SDR: SV0qYb63niNV9GMArm2g502LOO41WCibREwQLWEdJpDSZOVJp3Wfeu2Ylls0Vzbg/P9gkErI/D AupL5AM/4/Zw== X-IronPort-AV: E=Sophos;i="5.77,368,1596524400"; d="scan'208";a="530165565" Received: from lusin-mobl1.ger.corp.intel.com (HELO localhost) ([10.252.53.81]) by orsmga005-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 12 Oct 2020 16:55:04 -0700 Date: Tue, 13 Oct 2020 02:55:02 +0300 From: Jarkko Sakkinen To: =?iso-8859-1?Q?Micka=EBl_Sala=FCn?= Cc: Alasdair Kergon , Mike Snitzer , Deven Bowers , Jaskaran Khurana , Milan Broz , dm-devel@redhat.com, linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org, =?iso-8859-1?Q?Micka=EBl_Sala=FCn?= Subject: Re: [PATCH v1] dm verity: Add support for signature verification with 2nd keyring Message-ID: <20201012235502.GA36149@linux.intel.com> References: <20201002071802.535023-1-mic@digikod.net> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: Organization: Intel Finland Oy - BIC 0357606-4 - Westendinkatu 7, 02160 Espoo Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Oct 09, 2020 at 11:50:03AM +0200, Micka?l Sala?n wrote: > Hi, > > What do you think about this patch? > > Regards, > Micka?l > > On 02/10/2020 09:18, Micka?l Sala?n wrote: > > From: Micka?l Sala?n > > > > Add a new DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING configuration > > to enable dm-verity signatures to be verified against the secondary > > trusted keyring. This allows certificate updates without kernel update > > and reboot, aligning with module and kernel (kexec) signature > > verifications. I'd prefer a bit more verbose phrasing, not least because I have never really even peeked at dm-verity, but it is also a good practice. You have the middle part of the story missing - explaining the semantics of how the feature leads to the aimed solution. /Jarkko