Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Petr Vorel <petr.vorel@gmail.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH v2] ima-evm-utils: Add as new package, version 1.2.1
Date: Thu, 1 Aug 2019 16:24:20 +0200	[thread overview]
Message-ID: <20190801142419.GA30389@dell5510> (raw)
In-Reply-To: <CANQCQpbTPuhm_a-SFei+RNdkRvPjXP5LZddPYqvAjoXTgTqD7g@mail.gmail.com>

Hi Matthew,

> > +++ b/package/ima-evm-utils/Config.in
> > @@ -0,0 +1,11 @@
> > +config BR2_PACKAGE_IMA_EVM_UTILS
> > +       bool "ima-evm-utils"
> > +       depends on BR2_USE_MMU # keyutils dependency: fork()
> > +       depends on !BR2_STATIC_LIBS # keyutils dependency: dlopen
> > +       select BR2_PACKAGE_OPENSSL
> > +       select BR2_PACKAGE_KEYUTILS
> > +       help
> > +         Linux Integrity Measurement Architecture (IMA)
> > +         Extended Verification Module (EVM) tools.

> Do you have a proposal for how to use these tools in an embedded
> environment where a filesystem needs to be "labeled/staged" offline
> with the signatures/hashes?

> The filesystem staging might be a good run time test case as well to
> show the end to end use where you execute a qemu which uses the IMA
> tools to authenticate apps executing from a filesystem you just built.

Yes I was thinking about it as well. While for some usage it's handy to have it
on the target, it'd be certainly helpful to offer functionality to do do
labelling filesystem with security.{ima,evm} extended attributes or with digital
signatures during stagging.

Kind regards,
Petr

  reply	other threads:[~2019-08-01 14:24 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-07-31 19:31 [Buildroot] [PATCH v2] ima-evm-utils: Add as new package, version 1.2.1 Petr Vorel
2019-07-31 19:33 ` Petr Vorel
2019-08-01 14:15 ` Matthew Weber
2019-08-01 14:24   ` Petr Vorel [this message]
2019-08-26 19:24 ` Petr Vorel
2019-10-01 18:56 ` Petr Vorel
2019-10-26 10:22 ` Matthew Weber
2019-10-26 11:22   ` Petr Vorel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20190801142419.GA30389@dell5510 \
    --to=petr.vorel@gmail.com \
    --cc=buildroot@busybox.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox