Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Add .github/CODEOWNERS | Lans Zhang | 2017-07-12 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | Fix the occurrence of checking the existence of signing keys | Lans Zhang | 2017-07-12 | 9 | -10/+8 | |
| | | | | | | packagegroups are not the end consumers of using user-key-store. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | key-store-rpm-pubkey: fix installation failure | Lans Zhang | 2017-07-11 | 1 | -2/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | packagegroup-efi-secure-boot/packagegroup-ima: depend on check_deploy_keys | Lans Zhang | 2017-07-11 | 2 | -0/+10 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README: fix a typo | Lans Zhang | 2017-07-11 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README: cleanup | Lans Zhang | 2017-07-11 | 1 | -24/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | keyutils: fix build failure with ppc | Lans Zhang | 2017-07-11 | 2 | -29/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README: cleanup | Lans Zhang | 2017-07-11 | 1 | -7/+3 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | user-key-store: don't call anonymous function | Lans Zhang | 2017-07-11 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | mokutil: code style fixup | Lans Zhang | 2017-07-11 | 1 | -7/+9 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | mokutil: add the COMPATIBLE_HOST | Lans Zhang | 2017-07-11 | 1 | -0/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: enable http boot support | Lans Zhang | 2017-07-11 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | secure-core-image: install lsb packagegroup | Lans Zhang | 2017-07-11 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-integrity: enable sign_rpm_ext to support rpm and file signing | Lans Zhang | 2017-07-11 | 2 | -0/+22 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | create-user-key-store.sh: clean up subject and support password protection ↵ | Lans Zhang | 2017-07-11 | 1 | -12/+23 | |
| | | | | | | for private key Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-secure-core: add RRECOMMENDS | Lans Zhang | 2017-07-11 | 1 | -0/+7 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-signing-key: replace the sample keys | Lans Zhang | 2017-07-11 | 14 | -283/+286 | |
| | | | | | | | - Remove USER@host from the certificate subject field - IMA signing key is protected by a password Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | base-file: mount securityfs | Lans Zhang | 2017-07-11 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | IMA: clean up IMA signing | Lans Zhang | 2017-07-11 | 3 | -178/+3 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | init: don't need to create /proc /sys and /run | Lans Zhang | 2017-07-05 | 1 | -1/+0 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | Clean up RDEPENDS | Lans Zhang | 2017-07-05 | 5 | -32/+64 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | cryptfs-tpm2: sync up with upstream | Lans Zhang | 2017-07-05 | 1 | -2/+6 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | cryptfs-tpm2: code style fixup | Lans Zhang | 2017-07-05 | 1 | -13/+15 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | init: clean up | Lans Zhang | 2017-07-04 | 1 | -80/+40 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | ima-policy: enable policy check | Lans Zhang | 2017-07-04 | 1 | -0/+3 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-ima: clean up code style and RDEPENDS | Lans Zhang | 2017-07-04 | 1 | -23/+20 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | init.ima: code style cleanup | Lans Zhang | 2017-07-04 | 1 | -14/+8 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | Code style fixup | Lans Zhang | 2017-07-04 | 4 | -21/+20 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-secure-core: clean up RDEPENDS | Lans Zhang | 2017-07-04 | 1 | -14/+29 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | packagegroup-ima*: clean up the RDEPENDS | Lans Zhang | 2017-07-04 | 2 | -11/+5 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-secure-core: renamed from initramfs-secure-core | Lans Zhang | 2017-07-04 | 2 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initramfs-secure-core: clean up /init script | Lans Zhang | 2017-07-04 | 2 | -15/+3 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-integrity: implement the system trusted cert and IMA trusted cert | Lans Zhang | 2017-07-04 | 11 | -80/+110 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-signing-key: enable authorityKeyIdentifier for x509 v3 | Lans Zhang | 2017-07-03 | 6 | -54/+57 | |
| | | | | | | | Otherwise the x509 parser in kernel cannot load a x509 certificate without authorityKeyIdentifier. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | seloader: sync up with upstream | Lans Zhang | 2017-07-03 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-signing-keys: use DER-formatted system trusted key and signed IMA ↵ | Lans Zhang | 2017-07-03 | 4 | -52/+52 | |
| | | | | | | trusted key Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | user-key-store: clean up the code style | Lans Zhang | 2017-07-03 | 1 | -80/+16 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | Use the DER-formatted system trusted key | Lans Zhang | 2017-07-03 | 3 | -7/+30 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | init: clean up code style | Lans Zhang | 2017-07-03 | 1 | -34/+30 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | Rename .pem to .crt | Lans Zhang | 2017-07-03 | 15 | -43/+24 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initramfs-secure-core: fix missing the license file | Lans Zhang | 2017-07-03 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initramfs-secure-core: define the /init script for the initramfs image | Lans Zhang | 2017-07-03 | 2 | -0/+162 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | kernel-initramfs: define this package to include the initramfs image for ↵ | Lans Zhang | 2017-07-03 | 2 | -0/+132 | |
| | | | | | | kernel boot Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | secure-core-image-initramfs: define the initramfs image type | Lans Zhang | 2017-07-03 | 1 | -0/+35 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | secure-core-image: clean up the code style | Lans Zhang | 2017-07-03 | 1 | -3/+10 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: fix OVMF crash | Lans Zhang | 2017-06-30 | 3 | -13/+45 | |
| | | | | | | | | - httpboot.o cannot be built if ".PRECIOUS: " is placed ahead of "<tab>CFLAGS +=". - uri pointer should not be freed if NULL. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: clean up the code style | Lans Zhang | 2017-06-30 | 1 | -27/+29 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | code style fixup | Lans Zhang | 2017-06-29 | 10 | -42/+51 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | create-user-key-store.sh: restructured for self-signing and ca signing | Lans Zhang | 2017-06-29 | 1 | -57/+51 | |
| | | | | | | Meanwhile, the IMA user key is signed by system user key. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | secure-core-image: install ima-related packages if ima feature configured | Lans Zhang | 2017-06-26 | 1 | -0/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> |