Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp1171152pxj; Fri, 21 May 2021 08:04:17 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwGlA+vRJjC8P1np3/YMxNs0kbM6lrBFmo7L+CC5tOf2kFk+B1XNhnfRwq3HOLgabgScGud X-Received: by 2002:a17:906:dcb:: with SMTP id p11mr10949375eji.117.1621609457548; Fri, 21 May 2021 08:04:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1621609457; cv=none; d=google.com; s=arc-20160816; b=Unzdxs7KTDIIDHMlZ/eLMy/nYudF+pMbPalx1Cs+3xSsf224graddximiOcEiJfBpK PHk/RkwIQhA+B7s3DX9ELSoYCnOK+xuogjtIx+zFLQQI5JaZKbmLCu5iuUkyLXmhz+03 m4r1OWE30w4nZv1HZOfa4m8aGgohnED3qdNi0zbMQ+3UX5KFSL45/UpStk+cbizJVwB0 g4mdf9ve1PVMNNC3cBZfPSxpdtMBClYFExydE94q+MknQd7f6ZB1fZ2aFO+4ZcWz8Vem K8hJhiRuK26C/vMgaXnRHaU9/PPB3UwVaRXrqt7vofmqP8eG33/vcu+nxxdntyGY+GRe sR5A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=X3k69m04PuZbxdWYLDIcQraEU5NvRX+5kOeqGtXEuow=; b=PBcc0nTzOFjGII4azfkosBKrqPxc3u4LZqwGKtmav20hM6fK1NwT7ghj0GnitceSjM a8SB6E1pU2sv6KhCQOAp7Ozt4Jdcbx+fkMO9byUk1udQbpbHcSyii1606VlyiaAiaR+l PCMFcalXkw4qmovN/7/gQt7Zxm1bIAJLyx7+/QLIAhsOwTGG2qbeOTAtQe6JEBxs3c7s /wOAGiDjU1kFfbZbxESiACYaybm190trZzMeXU71e/h4pAyXiiP2a3yNmwJt1JKTvWsP xI9yURvp+vo7NlVNPJQk0UvuV7WUC4vcmHheOQdgki4HSOfgW/Tg6H0PVFIWiXiHwmWm heOA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=fQ3xJQul; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id m1si5823730edb.244.2021.05.21.08.03.52; Fri, 21 May 2021 08:04:17 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=fQ3xJQul; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233248AbhETQBP (ORCPT + 99 others); Thu, 20 May 2021 12:01:15 -0400 Received: from mail.kernel.org ([198.145.29.99]:55222 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233193AbhETQBN (ORCPT ); Thu, 20 May 2021 12:01:13 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id 74430610A8; Thu, 20 May 2021 15:59:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1621526392; bh=J7btpZi7y4UrNwPzAa1BVbYzDrZodtP7CYkne7Yl2sc=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=fQ3xJQulbZOJceu/CiUOV/PKvZizFJd+4pjhZXdQ8SrEV5QBUbg93eKR/6iZGSGlB 7U4va4HE78FbtLPpquvufFwsEEGpjUlN6ATCEomn66C2qR0BINn4xtlgQXFZWlhquV 4BgSBDmmxfd0uFb4l4tv2jNHYouArLkAI8IoNVJarn81kyDkpBOS5ub53C6oIFG+k/ 9997NrXEQGn2Y88I4RSx3Arv+vZMkJTgsZFSRvfRLUvQ75aIYYiEfIdFzeaTvLLrgK dybmGZ+XhtWA3LVJKzRal5i2E7O1Usu/yeoKa9/GjILrleKzpNrFwr9WA7QFv7XiOy IrsVsOy13O9ww== Date: Thu, 20 May 2021 18:59:49 +0300 From: Jarkko Sakkinen To: Eric Snowberg Cc: keyrings@vger.kernel.org, linux-integrity@vger.kernel.org, dhowells@redhat.com, dwmw2@infradead.org, dmitry.kasatkin@gmail.com, jmorris@namei.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, zohar@linux.ibm.com, torvalds@linux-foundation.org, serge@hallyn.com, James.Bottomley@hansenpartnership.com, pjones@redhat.com, glin@suse.com Subject: Re: [RFC PATCH 1/3] keys: Add ability to trust the platform keyring Message-ID: References: <20210517225714.498032-1-eric.snowberg@oracle.com> <20210517225714.498032-2-eric.snowberg@oracle.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20210517225714.498032-2-eric.snowberg@oracle.com> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, May 17, 2021 at 06:57:12PM -0400, Eric Snowberg wrote: > Add the ability to allow the secondary_trusted keyring to trust > keys in the platform keyring. This is done by doing a key_link What this looks for me doing is to *replace* the secondary trusted keyring with the platform keyring. So this should be "Add ability to replace the secondary trusted keyring with the platform keyring." This is what the code change is actually doing so it would be nice to say it out loud. > of the platform_trusted_keys to the secondary_trusted_keys. > After they are linked, the platform_trusted_keys can be used for > validation instead of the secondary_trusted_keys if the user > chooses. This functionality will be used in a follow on patch. > > Signed-off-by: Eric Snowberg /Jarkko