summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>2019-09-30 17:10:15 +0300
committerDmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>2019-09-30 17:10:15 +0300
commitf2db9e0de6934f3533449056eadd646784833d1f (patch)
treebfacfc37866ca0f86892202a4146c0470942cc43
parentb41010c80c98ed5d0f987a97cb927660bc494821 (diff)
downloadmeta-secure-core-f2db9e0de6934f3533449056eadd646784833d1f.tar.gz
meta-integrity: fix documentation
Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>
-rw-r--r--meta-integrity/README.md9
1 files changed, 5 insertions, 4 deletions
diff --git a/meta-integrity/README.md b/meta-integrity/README.md
index ad17c05..32365e9 100644
--- a/meta-integrity/README.md
+++ b/meta-integrity/README.md
@@ -110,14 +110,15 @@ default, the sample keys are used for the purpose of development and
110demonstration. Please ensure you know what your risk is to use the sample keys 110demonstration. Please ensure you know what your risk is to use the sample keys
111in your product, because they are completely public. 111in your product, because they are completely public.
112 112
113If sample keys are used, the private IMA key is installed as /etc/keys/x509_ima.key. 113Private keys are not installed into the target image. If you understand your
114risks, you can copy them to your target file system or to an external storage.
114 115
115A typical signing command is as following: 116If you do so, a typical signing command is as following:
116 117
117 # evmctl ima_sign --hashalgo sha256 --key /etc/keys/x509_ima.key --pass=<passowrd> /path/to/file 118 # evmctl ima_sign --hashalgo sha256 --key path/to/x509_ima.key --pass=<passowrd> /path/to/file
118or 119or
119 120
120 # evmctl ima_sign --hashalgo sha256 --key /etc/keys/x509_ima.key --pass=<passowrd> -r /path/to/directory 121 # evmctl ima_sign --hashalgo sha256 --key /path/to/x509_ima.key --pass=<passowrd> -r /path/to/directory
121 122
122The following command can be used to verify a file's IMA signature with specified certificate: 123The following command can be used to verify a file's IMA signature with specified certificate:
123 124