Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | systemd: work around circular dependency chains found if systemd is ↵ | Lans Zhang | 2017-08-09 | 1 | -4/+4 | |
| | | | | | | configured to enable cryptsetup Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | systemd: fix the conditions of PACKAGECONFIG for ima and cryptsetup | Lans Zhang | 2017-08-04 | 2 | -2/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | systemd: enable ima and cryptsetup | Lans Zhang | 2017-08-04 | 2 | -0/+8 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | cryptsetup: depend on lvm2 to include dmsetup | Lans Zhang | 2017-08-04 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | cryptfs-tpm2: fix RDEPENDS | Lans Zhang | 2017-08-04 | 1 | -5/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-encrypted-storage: depend on meta-oe | Lans Zhang | 2017-08-04 | 1 | -0/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | kernel-initramfs: set the default priority to -1 | Lans Zhang | 2017-08-03 | 1 | -0/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: sync up with upstream | Lans Zhang | 2017-08-03 | 2 | -8/+8 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: don't set CSV boot entry as the first boot option | Lans Zhang | 2017-08-01 | 2 | -0/+50 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | create-user-key-store.sh: self-sign KEK and DB | Lans Zhang | 2017-08-01 | 1 | -2/+2 | |
| | | | | | | | UEFI spec never ask for the fact that KEK must be signed by PK and DB must be signed by KEK. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README.md: simplify the commits for boot flow | Lans Zhang | 2017-07-31 | 1 | -5/+5 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | rpm: remove PACKAGECONFIG[imaevm] | Lans Zhang | 2017-07-28 | 1 | -1/+0 | |
| | | | | | | This setting is already merged to oe-core. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-secure-core: code style fixup | Lans Zhang | 2017-07-28 | 7 | -24/+27 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | grub-efi: remove the depreciated replacement for initrd= parameter | Lans Zhang | 2017-07-28 | 1 | -7/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | grub/boot-menu.inc: use linux and initrd commands instead of chainloader to ↵ | Lans Zhang | 2017-07-27 | 1 | -2/+4 | |
| | | | | | | | | boot kernel Since bzImage is not signed during the build. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2.0-tss: remove systemd from inherit command | Lans Zhang | 2017-07-27 | 1 | -1/+1 | |
| | | | | | | | The resource manager provided by this package is not used any more. Thus its systemd-related settings should be removed. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | packagegroup-encrypted-storage.inc: add cryptfs-tpm2 | Lans Zhang | 2017-07-27 | 1 | -0/+4 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-secure-core: install udevd and udevadm provided by either ↵ | Lans Zhang | 2017-07-26 | 1 | -3/+2 | |
| | | | | | | eudev or udev Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | initrdscripts-secure-core: don't install sysvinit | Lans Zhang | 2017-07-26 | 1 | -2/+0 | |
| | | | | | | /sbin/init should be covered by rootfs not here. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | user-key-store.bbclass: set SYSTEM_TRUSTED only if ima is configured | Lans Zhang | 2017-07-25 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | user-key-store.bbclass: don't run check_deploy_keys in parallel | Lans Zhang | 2017-07-25 | 1 | -0/+2 | |
| | | | | | | | | | | | Set lockfile for task check_deploy_keys() to avoid the race error from 'cp -af': cp: cannot create regular file '.../tmp/deploy/images/intel-x86-64/ sample-keys/uefi_sb_keys/DBX/DBX.key': File exists Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com> Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | IMA: move the default policy file to /etc/ima directory | Lans Zhang | 2017-07-25 | 2 | -8/+10 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-efi-secure-boot/README: update to reflect using fallback to chainloader ↵ | Lans Zhang | 2017-07-25 | 1 | -12/+17 | |
| | | | | | | SELoader Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: use fallback loading SELoader | Lans Zhang | 2017-07-24 | 4 | -24/+69 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | sbsigntool: code style fixup | Lans Zhang | 2017-07-24 | 1 | -21/+40 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | efivar: clean up | Lans Zhang | 2017-07-24 | 2 | -57/+0 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-efi-secure-boot: depend on meta-perl | Lans Zhang | 2017-07-24 | 2 | -17/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | shim: update to the latest | Lans Zhang | 2017-07-24 | 2 | -35/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | openssl-tpm-engine: fix cmdline parsing failure on arm platform | Lans Zhang | 2017-07-21 | 2 | -0/+35 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2simulator: add the native build | Lans Zhang | 2017-07-21 | 2 | -0/+65 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | trouser: a minor fix for debug package | Lans Zhang | 2017-07-21 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | IMA: allow to write policy but deny to read policy | Lans Zhang | 2017-07-20 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-tpm2: code style fixup | Lans Zhang | 2017-07-20 | 6 | -6/+9 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tss2.0-tss: don't create tss user account | Lans Zhang | 2017-07-20 | 1 | -6/+0 | |
| | | | | | | | This user account is created by tpm2-abrmd which replaces the resourcemgr originally supplied by this recipe. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2-abrmd: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 2 | -326/+39 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2.0-tools: clean up .m4 | Lans Zhang | 2017-07-20 | 4 | -232/+2 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2.0-tss: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 7 | -642/+45 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm2.0-tools: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 3 | -43/+31 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-secure-core: define the oe index name | Lans Zhang | 2017-07-20 | 7 | -0/+16 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm-tools: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 5 | -45/+43 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tss-testsuite: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 4 | -99/+66 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | tpm-quote-tools: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 2 | -26/+27 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | pcr-extend: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 2 | -21/+27 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | openssl-tpm-engine: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 1 | -37/+45 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-secure-core: define new image type secure-core-minimal-image | Lans Zhang | 2017-07-20 | 3 | -30/+35 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | meta-tpm: code style fixup | Lans Zhang | 2017-07-20 | 7 | -18/+56 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | cryptfs-tpm2: change the SECTION | Lans Zhang | 2017-07-20 | 1 | -1/+1 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | trousers: update to the latest and code style fixup | Lans Zhang | 2017-07-20 | 4 | -120/+117 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README: RPM5 signing is not supported | Lans Zhang | 2017-07-19 | 1 | -1/+1 | |
| | | | | | | Instead, RPM4 is supported from now on. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | |||||
* | README: don't include meta-secure-core as the sub-layer | Lans Zhang | 2017-07-19 | 1 | -2/+0 | |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> |