linux-xiaomi-chiron/security
Eric Snowberg 74f5e30051 integrity: Trust MOK keys if MokListTrustedRT found
A new Machine Owner Key (MOK) variable called MokListTrustedRT has been
introduced in shim. When this UEFI variable is set, it indicates the
end-user has made the decision themselves that they wish to trust MOK keys
within the Linux trust boundary.  It is not an error if this variable
does not exist. If it does not exist, the MOK keys should not be trusted
within the kernel.

Signed-off-by: Eric Snowberg <eric.snowberg@oracle.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
2022-03-08 13:55:52 +02:00
..
apparmor
bpf
integrity integrity: Trust MOK keys if MokListTrustedRT found 2022-03-08 13:55:52 +02:00
keys KEYS: trusted: Avoid calling null function trusted_key_exit 2022-03-08 13:55:52 +02:00
landlock
loadpin
lockdown
safesetid
selinux selinux: fix misuse of mutex_is_locked() 2022-02-22 18:02:58 -05:00
smack
tomoyo
yama
commoncap.c
device_cgroup.c
inode.c
Kconfig
Kconfig.hardening
lsm_audit.c
Makefile
min_addr.c
security.c