From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Howells Subject: Re: [PATCH 08/30] kexec_file: Restrict at runtime if the kernel is locked down Date: Thu, 11 Jan 2018 12:43:20 +0000 Message-ID: <12880.1515674600@warthog.procyon.org.uk> References: <20180111115915.dejachty3l7fwpmf@dwarf.suse.cz> <151024863544.28329.2436580122759221600.stgit@warthog.procyon.org.uk> <151024869793.28329.4817577607302613028.stgit@warthog.procyon.org.uk> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Return-path: In-Reply-To: <20180111115915.dejachty3l7fwpmf-Q+Z4OdfSLAKN3ZZ/Hiejyg@public.gmane.org> Content-ID: <12879.1515674600.1-S6HVgzuS8uM4Awkfq6JHfwNdhmdF6hFW@public.gmane.org> Sender: linux-efi-owner-u79uwXL29TY76Z2rM5mHXA@public.gmane.org To: Jiri Bohac Cc: dhowells-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, linux-security-module-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, gnomes-qBU/x9rampVanCEyBjwyrvXRex20P6io@public.gmane.org, linux-efi-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, jforbes-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, Chun-Yi Lee List-Id: linux-efi@vger.kernel.org Jiri Bohac wrote: > I don't like the idea that the lockdown (which is a runtime > thing) requires a compile time option (KEXEC_VERIFY_SIG) that > forces the verification even when the kernel is then not locked > down at runtime. It doesn't. The EPERM only triggers if: (1) File signatures aren't mandatory (ie. CONFIG_KEXEC_VERIFY_SIG) is not set, and (2) you're not using IMA appraisal to validate the file contents, and (3) lockdown mode is enabled. If file signatures are mandatory or IMA appraisal is in use, then the lockdown state doesn't need to be checked. David From mboxrd@z Thu Jan 1 00:00:00 1970 From: dhowells@redhat.com (David Howells) Date: Thu, 11 Jan 2018 12:43:20 +0000 Subject: [PATCH 08/30] kexec_file: Restrict at runtime if the kernel is locked down In-Reply-To: <20180111115915.dejachty3l7fwpmf@dwarf.suse.cz> References: <20180111115915.dejachty3l7fwpmf@dwarf.suse.cz> <151024863544.28329.2436580122759221600.stgit@warthog.procyon.org.uk> <151024869793.28329.4817577607302613028.stgit@warthog.procyon.org.uk> Message-ID: <12880.1515674600@warthog.procyon.org.uk> To: linux-security-module@vger.kernel.org List-Id: linux-security-module.vger.kernel.org Jiri Bohac wrote: > I don't like the idea that the lockdown (which is a runtime > thing) requires a compile time option (KEXEC_VERIFY_SIG) that > forces the verification even when the kernel is then not locked > down at runtime. It doesn't. The EPERM only triggers if: (1) File signatures aren't mandatory (ie. CONFIG_KEXEC_VERIFY_SIG) is not set, and (2) you're not using IMA appraisal to validate the file contents, and (3) lockdown mode is enabled. If file signatures are mandatory or IMA appraisal is in use, then the lockdown state doesn't need to be checked. David -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html From mboxrd@z Thu Jan 1 00:00:00 1970 Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S934175AbeAKMnZ (ORCPT + 1 other); Thu, 11 Jan 2018 07:43:25 -0500 Received: from mx1.redhat.com ([209.132.183.28]:44670 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752735AbeAKMnX (ORCPT ); Thu, 11 Jan 2018 07:43:23 -0500 Organization: Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 From: David Howells In-Reply-To: <20180111115915.dejachty3l7fwpmf@dwarf.suse.cz> References: <20180111115915.dejachty3l7fwpmf@dwarf.suse.cz> <151024863544.28329.2436580122759221600.stgit@warthog.procyon.org.uk> <151024869793.28329.4817577607302613028.stgit@warthog.procyon.org.uk> To: Jiri Bohac Cc: dhowells@redhat.com, linux-security-module@vger.kernel.org, gnomes@lxorguk.ukuu.org.uk, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, jforbes@redhat.com, Chun-Yi Lee Subject: Re: [PATCH 08/30] kexec_file: Restrict at runtime if the kernel is locked down MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-ID: <12879.1515674600.1@warthog.procyon.org.uk> Date: Thu, 11 Jan 2018 12:43:20 +0000 Message-ID: <12880.1515674600@warthog.procyon.org.uk> X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Thu, 11 Jan 2018 12:43:23 +0000 (UTC) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Return-Path: Jiri Bohac wrote: > I don't like the idea that the lockdown (which is a runtime > thing) requires a compile time option (KEXEC_VERIFY_SIG) that > forces the verification even when the kernel is then not locked > down at runtime. It doesn't. The EPERM only triggers if: (1) File signatures aren't mandatory (ie. CONFIG_KEXEC_VERIFY_SIG) is not set, and (2) you're not using IMA appraisal to validate the file contents, and (3) lockdown mode is enabled. If file signatures are mandatory or IMA appraisal is in use, then the lockdown state doesn't need to be checked. David