From: Mimi Zohar <zohar@linux.ibm.com>
To: Coiby Xu <coxu@redhat.com>,
linux-integrity@vger.kernel.org,
linux-security-module <linux-security-module@vger.kernel.org>
Cc: Eric Biederman <ebiederm@xmission.com>,
"open list:KEXEC" <kexec@lists.infradead.org>,
open list <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] kexec_file: ima: allow loading a kernel with its IMA signature verified
Date: Wed, 12 Jul 2023 14:31:43 -0400 [thread overview]
Message-ID: <eaa1f1901abbceb2edc0aadaa94d9d959413c984.camel@linux.ibm.com> (raw)
In-Reply-To: <20230711031604.717124-1-coxu@redhat.com>
[Cc'ing the LSM mailing list.]
On Tue, 2023-07-11 at 11:16 +0800, Coiby Xu wrote:
> When IMA has verified the signature of the kernel image, kexec'ing this
> kernel should be allowed.
>
> Fixes: af16df54b89d ("ima: force signature verification when CONFIG_KEXEC_SIG is configured")
> Signed-off-by: Coiby Xu <coxu@redhat.com>
The original commit 29d3c1c8dfe7 ("kexec: Allow kexec_file() with
appropriate IMA policy when locked down") was not in lieu of the PE-
COFF signature, but allowed using the IMA signature on other
architectures.
Currently on systems with both PE-COFF and IMA signatures, both
signatures are verified, assuming the file is in the IMA policy. If
either signature verification fails, the kexec fails.
With this patch, only the IMA signature would be verified.
> ---
> kernel/kexec_file.c | 14 +++++++++-----
> 1 file changed, 9 insertions(+), 5 deletions(-)
>
> diff --git a/kernel/kexec_file.c b/kernel/kexec_file.c
> index 881ba0d1714c..96fce001fbc0 100644
> --- a/kernel/kexec_file.c
> +++ b/kernel/kexec_file.c
> @@ -162,6 +162,13 @@ kimage_validate_signature(struct kimage *image)
> ret = kexec_image_verify_sig(image, image->kernel_buf,
> image->kernel_buf_len);
> if (ret) {
> + /*
> + * If the kernel image already has its IMA signature verified, permit it.
> + */
> + if (ima_appraise_signature(READING_KEXEC_IMAGE)) {
> + pr_notice("The kernel image already has its IMA signature verified.\n");
> + return 0;
> + }
>
> if (sig_enforce) {
> pr_notice("Enforced kernel signature verification failed (%d).\n", ret);
> @@ -169,12 +176,9 @@ kimage_validate_signature(struct kimage *image)
> }
>
> /*
> - * If IMA is guaranteed to appraise a signature on the kexec
> - * image, permit it even if the kernel is otherwise locked
> - * down.
> + * When both IMA and KEXEC_SIG fail in lockdown mode, reject it.
> */
> - if (!ima_appraise_signature(READING_KEXEC_IMAGE) &&
> - security_locked_down(LOCKDOWN_KEXEC))
> + if (security_locked_down(LOCKDOWN_KEXEC))
> return -EPERM;
>
> pr_debug("kernel signature verification failed (%d).\n", ret);
_______________________________________________
kexec mailing list
kexec@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kexec
next prev parent reply other threads:[~2023-07-12 18:31 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-07-11 3:16 [PATCH] kexec_file: ima: allow loading a kernel with its IMA signature verified Coiby Xu
2023-07-12 18:31 ` Mimi Zohar [this message]
2023-07-13 17:59 ` Eric Snowberg
2023-07-14 2:29 ` Coiby Xu
2023-07-14 15:50 ` Eric Snowberg
2023-07-14 1:46 ` Coiby Xu
2023-07-14 15:02 ` Mimi Zohar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=eaa1f1901abbceb2edc0aadaa94d9d959413c984.camel@linux.ibm.com \
--to=zohar@linux.ibm.com \
--cc=coxu@redhat.com \
--cc=ebiederm@xmission.com \
--cc=kexec@lists.infradead.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox