Mimi Zohar 16c267aac8 ima: based on policy require signed kexec kernel images
The original kexec_load syscall can not verify file signatures, nor can
the kexec image be measured.  Based on policy, deny the kexec_load
syscall.

Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Cc: Eric Biederman <ebiederm@xmission.com>
Cc: Kees Cook <keescook@chromium.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: James Morris <james.morris@microsoft.com>
2018-07-16 12:31:57 -07:00
..
2018-06-06 08:16:33 -07:00
2018-06-11 18:15:22 -07:00
2018-06-15 18:10:01 -03:00
2018-06-21 07:22:30 +09:00
2018-06-10 13:01:12 -07:00
2018-06-11 18:19:45 -07:00
2018-06-06 09:08:38 -07:00
2018-06-12 10:09:03 -07:00
2018-06-24 06:33:54 +08:00
2018-06-17 05:00:24 +09:00
2018-06-23 20:44:11 +08:00