diff options
| author | Nayna Jain <nayna@linux.ibm.com> | 2023-08-15 07:27:22 -0400 |
|---|---|---|
| committer | Jarkko Sakkinen <jarkko@kernel.org> | 2023-08-17 20:12:35 +0000 |
| commit | 44e69ea53892f18e8753943a4376de20b076c3fe (patch) | |
| tree | c20731fd41dfedd00dd77d34c0e66b0b806bfa79 /security/integrity/platform_certs/keyring_handler.c | |
| parent | d7d91c4743c4ef0f60b7556d2794b6dd27cda373 (diff) | |
| download | linux-44e69ea53892f18e8753943a4376de20b076c3fe.tar.gz linux-44e69ea53892f18e8753943a4376de20b076c3fe.tar.bz2 linux-44e69ea53892f18e8753943a4376de20b076c3fe.zip | |
integrity: PowerVM support for loading third party code signing keys
On secure boot enabled PowerVM LPAR, third party code signing keys are
needed during early boot to verify signed third party modules. These
third party keys are stored in moduledb object in the Platform
KeyStore (PKS).
Load third party code signing keys onto .secondary_trusted_keys keyring.
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Reviewed-and-tested-by: Mimi Zohar <zohar@linux.ibm.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Nageswara R Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Diffstat (limited to 'security/integrity/platform_certs/keyring_handler.c')
| -rw-r--r-- | security/integrity/platform_certs/keyring_handler.c | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/security/integrity/platform_certs/keyring_handler.c b/security/integrity/platform_certs/keyring_handler.c index 586027b9a3f5..13ea17207902 100644 --- a/security/integrity/platform_certs/keyring_handler.c +++ b/security/integrity/platform_certs/keyring_handler.c @@ -78,6 +78,14 @@ __init efi_element_handler_t get_handler_for_ca_keys(const efi_guid_t *sig_type) return NULL; } +__init efi_element_handler_t get_handler_for_code_signing_keys(const efi_guid_t *sig_type) +{ + if (efi_guidcmp(*sig_type, efi_cert_x509_guid) == 0) + return add_to_secondary_keyring; + + return NULL; +} + /* * Return the appropriate handler for particular signature list types found in * the UEFI dbx and MokListXRT tables. |
