From: Will Deacon <will@kernel.org>
To: Mimi Zohar <zohar@linux.ibm.com>
Cc: Coiby Xu <coxu@redhat.com>,
kexec@lists.infradead.org, linux-integrity@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
Michal Suchanek <msuchanek@suse.de>, Baoquan He <bhe@redhat.com>,
Dave Young <dyoung@redhat.com>,
"Eric W . Biederman" <ebiederm@xmission.com>,
Chun-Yi Lee <jlee@suse.com>
Subject: Re: [PATCH v9 0/4] unify the keyrings of arm64 and s390 with x86 to verify kexec'ed kernel signature
Date: Wed, 6 Jul 2022 12:48:07 +0100 [thread overview]
Message-ID: <20220706114806.GB2403@willie-the-truck> (raw)
In-Reply-To: <711440de6340ef6ad73e4db5edd36fc391b8a11d.camel@linux.ibm.com>
On Wed, Jul 06, 2022 at 07:35:36AM -0400, Mimi Zohar wrote:
> On Mon, 2022-07-04 at 09:51 +0800, Coiby Xu wrote:
> > Currently when loading a kernel image via the kexec_file_load() system
> > call, x86 can make use of three keyrings i.e. the .builtin_trusted_keys,
> > .secondary_trusted_keys and .platform keyrings to verify a signature.
> > However, arm64 and s390 can only use the .builtin_trusted_keys and
> > .platform keyring respectively. For example, one resulting problem is
> > kexec'ing a kernel image would be rejected with the error "Lockdown:
> > kexec: kexec of unsigned images is restricted; see man
> > kernel_lockdown.7".
> >
> > This patch set enables arm64 and s390 to make use of the same keyrings
> > as x86 to verify the signature kexec'ed kernel image.
[...]
> > For arm64, the tests were done as follows,
> > 1. build 5.19.0-rc2
> > 2. generate keys and add them to .secondary_trusted_keys, MOK, UEFI
> > db;
> > 3. sign different kernel images with different keys including keys
> > from .builtin_trusted_key, .secondary_trusted_keys keyring, a UEFI db
> > key and MOK key
> > 4. Without lockdown, all kernel images can be kexec'ed; with lockdown
> > enabled, only the kernel image signed by the key from the
> > .builtin_trusted_key keyring can be kexec'ed
>
> Just confirming, for arm64, this patch set allows verifying the
> kexec'ed kernel image signature using keys on either the .platform or
> .secondary_trusted_keys keyrings.
It looks like this series is ready to go, but it's not clear who should
pick it up. Eric -- would you be the best person? Otherwise, I'm happy to
take it via the arm64 tree (on its own branch) if that would be helpful.
Thanks,
Will
next prev parent reply other threads:[~2022-07-06 11:48 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-07-04 1:51 [PATCH v9 0/4] unify the keyrings of arm64 and s390 with x86 to verify kexec'ed kernel signature Coiby Xu
2022-07-04 1:51 ` [PATCH v9 1/4] kexec: clean up arch_kexec_kernel_verify_sig Coiby Xu
2022-07-04 1:51 ` [PATCH v9 2/4] kexec, KEYS: make the code in bzImage64_verify_sig generic Coiby Xu
2022-07-04 1:52 ` [PATCH v9 3/4] arm64: kexec_file: use more system keyrings to verify kernel image signature Coiby Xu
2022-07-04 1:52 ` [PATCH v9 4/4] kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification Coiby Xu
2022-07-06 11:35 ` [PATCH v9 0/4] unify the keyrings of arm64 and s390 with x86 to verify kexec'ed kernel signature Mimi Zohar
2022-07-06 11:48 ` Will Deacon [this message]
2022-07-06 14:33 ` Mimi Zohar
2022-07-07 14:10 ` Coiby Xu
2022-07-07 22:28 ` Mimi Zohar
2022-07-14 13:48 ` Coiby Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220706114806.GB2403@willie-the-truck \
--to=will@kernel.org \
--cc=bhe@redhat.com \
--cc=coxu@redhat.com \
--cc=dyoung@redhat.com \
--cc=ebiederm@xmission.com \
--cc=jlee@suse.com \
--cc=kexec@lists.infradead.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-integrity@vger.kernel.org \
--cc=msuchanek@suse.de \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox