Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | sign_rpm_ext: set default GPG_PATH if it is not specified (#2) | yunguowei | 2017-08-19 | 1 | -0/+15 |
| | | | | | | | | | | | commit 52bf3b6636f95a(meta-integrity: move gpg keyring initialization to signing-keys) tried to initialize keyring in the task check_public_keys of the recipe signing-keys. However, it does work with the recipe signing-keys only, and GPG_PATH can't be passed to other recipes. We bring the python anonymous function back, and it makes sure GPG_PATH is set before signing the packages for every recipe. Signed-off-by: Yunguo Wei <yunguo.wei@windriver.com> | ||||
* | meta-integrity: move gpg keyring initialization to signing-keys | Jia Zhang | 2017-08-17 | 2 | -38/+37 |
| | | | | Signed-off-by: Jia Zhang <lans.zhang2008@gmail.com> | ||||
* | sign_rpm_ext: support RPM signing | Lans Zhang | 2017-08-17 | 1 | -6/+45 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | ima-evm-utils: support to build with openssl-1.1.x | Lans Zhang | 2017-08-16 | 2 | -0/+300 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | README.md: update reference links | Lans Zhang | 2017-08-16 | 1 | -2/+2 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-integrity/README.md: update | Lans Zhang | 2017-08-16 | 1 | -12/+25 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | init.ima: clean up and allow to load extra IMA policies from the real rootfs | Lans Zhang | 2017-08-15 | 1 | -10/+18 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | ima_policy: update the comment | Lans Zhang | 2017-08-15 | 1 | -1/+2 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-integrity/README.md: update | Lans Zhang | 2017-08-15 | 1 | -15/+14 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-integrity/README.md: update | Lans Zhang | 2017-08-15 | 1 | -30/+38 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | systemd: fix the conditions of PACKAGECONFIG for ima and cryptsetup | Lans Zhang | 2017-08-04 | 1 | -1/+1 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | systemd: enable ima and cryptsetup | Lans Zhang | 2017-08-04 | 1 | -0/+4 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | rpm: remove PACKAGECONFIG[imaevm] | Lans Zhang | 2017-07-28 | 1 | -1/+0 |
| | | | | | | This setting is already merged to oe-core. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-secure-core: code style fixup | Lans Zhang | 2017-07-28 | 2 | -16/+19 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | IMA: move the default policy file to /etc/ima directory | Lans Zhang | 2017-07-25 | 2 | -8/+10 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | IMA: allow to write policy but deny to read policy | Lans Zhang | 2017-07-20 | 1 | -1/+1 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-secure-core: define the oe index name | Lans Zhang | 2017-07-20 | 1 | -0/+2 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | sign_rpm_ext: remove the test lines | Lans Zhang | 2017-07-19 | 1 | -4/+0 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | IMA: enable RPM file signing if ima is configured | Lans Zhang | 2017-07-19 | 1 | -1/+1 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | rpm: allow to enable IMA signing | Lans Zhang | 2017-07-18 | 12 | -0/+805 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | Fix the occurrence of checking the existence of signing keys | Lans Zhang | 2017-07-12 | 1 | -5/+0 |
| | | | | | | packagegroups are not the end consumers of using user-key-store. Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | packagegroup-efi-secure-boot/packagegroup-ima: depend on check_deploy_keys | Lans Zhang | 2017-07-11 | 1 | -0/+5 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | keyutils: fix build failure with ppc | Lans Zhang | 2017-07-11 | 2 | -29/+1 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-integrity: enable sign_rpm_ext to support rpm and file signing | Lans Zhang | 2017-07-11 | 2 | -0/+22 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | base-file: mount securityfs | Lans Zhang | 2017-07-11 | 1 | -0/+1 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | IMA: clean up IMA signing | Lans Zhang | 2017-07-11 | 3 | -178/+3 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | Clean up RDEPENDS | Lans Zhang | 2017-07-05 | 1 | -1/+0 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | ima-policy: enable policy check | Lans Zhang | 2017-07-04 | 1 | -0/+3 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | initrdscripts-ima: clean up code style and RDEPENDS | Lans Zhang | 2017-07-04 | 1 | -23/+20 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | init.ima: code style cleanup | Lans Zhang | 2017-07-04 | 1 | -14/+8 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | Code style fixup | Lans Zhang | 2017-07-04 | 3 | -7/+6 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | packagegroup-ima*: clean up the RDEPENDS | Lans Zhang | 2017-07-04 | 2 | -11/+5 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-integrity: implement the system trusted cert and IMA trusted cert | Lans Zhang | 2017-07-04 | 2 | -4/+9 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | Use the DER-formatted system trusted key | Lans Zhang | 2017-07-03 | 1 | -3/+4 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | code style fixup | Lans Zhang | 2017-06-29 | 1 | -3/+5 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | IMA: refresh kernel cfg | Lans Zhang | 2017-06-26 | 7 | -23/+22 |
| | | | | Signed-off-by: Lans Zhang <jia.zhang@windriver.com> | ||||
* | meta-secure-core: initial commit | Lans Zhang | 2017-06-22 | 29 | -0/+1003 |
Signed-off-by: Lans Zhang <jia.zhang@windriver.com> |