aboutsummaryrefslogtreecommitdiffstatshomepage
path: root/certs
diff options
context:
space:
mode:
authorTHOBY Simon <Simon.THOBY@viveris.fr>2021-08-16 08:10:59 +0000
committerMimi Zohar <zohar@linux.ibm.com>2021-08-16 17:30:41 -0400
commit50f742dd91474e7f4954bf88d094eede59783883 (patch)
tree1e166fbbcf7811a2c9a9f67d330139345b1b872e /certs
parentIMA: remove the dependency on CRYPTO_MD5 (diff)
downloadwireguard-linux-50f742dd91474e7f4954bf88d094eede59783883.tar.xz
wireguard-linux-50f742dd91474e7f4954bf88d094eede59783883.zip
IMA: block writes of the security.ima xattr with unsupported algorithms
By default, writes to the extended attributes security.ima will be allowed even if the hash algorithm used for the xattr is not compiled in the kernel (which does not make sense because the kernel would not be able to appraise that file as it lacks support for validating the hash). Prevent and audit writes to the security.ima xattr if the hash algorithm used in the new value is not available in the current kernel. Signed-off-by: THOBY Simon <Simon.THOBY@viveris.fr> Reviewed-by: Lakshmi Ramasubramanian <nramas@linux.microsoft.com> Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Diffstat (limited to 'certs')
0 files changed, 0 insertions, 0 deletions