kexec, KEYS, s390: Make use of built-in and secondary keyring for signature verification
stable inclusion from stable-v5.10.137 commit 539c20ad260ef0f8cd3188e1950b018fff9a631b category: bugfix bugzilla: https://gitee.com/openeuler/kernel/issues/I60PLB Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=539c20ad260ef0f8cd3188e1950b018fff9a631b -------------------------------- [ Upstream commit 0828c4a3 ] commit e23a8020 ("s390/kexec_file: Signature verification prototype") adds support for KEXEC_SIG verification with keys from platform keyring but the built-in keys and secondary keyring are not used. Add support for the built-in keys and secondary keyring as x86 does. Fixes: e23a8020 ("s390/kexec_file: Signature verification prototype") Cc: stable@vger.kernel.org Cc: Philipp Rudo <prudo@linux.ibm.com> Cc: kexec@lists.infradead.org Cc: keyrings@vger.kernel.org Cc: linux-security-module@vger.kernel.org Signed-off-by:Michal Suchanek <msuchanek@suse.de> Reviewed-by:
"Lee, Chun-Yi" <jlee@suse.com> Acked-by:
Baoquan He <bhe@redhat.com> Signed-off-by:
Coiby Xu <coxu@redhat.com> Acked-by:
Heiko Carstens <hca@linux.ibm.com> Signed-off-by:
Mimi Zohar <zohar@linux.ibm.com> Signed-off-by:
Sasha Levin <sashal@kernel.org> Signed-off-by:
Zheng Zengkai <zhengzengkai@huawei.com> Reviewed-by:
Wei Li <liwei391@huawei.com>
Loading
Please sign in to comment