kexec, KEYS: make the code in bzImage64_verify_sig generic
commit 278311e4 ("kexec, KEYS: Make use of platform keyring for signature verify") adds platform keyring support on x86 kexec but not arm64. The code in bzImage64_verify_sig uses the keys on the .builtin_trusted_keys, .machine, if configured and enabled, .secondary_trusted_keys, also if configured, and .platform keyrings to verify the signed kernel image as PE file. Cc: kexec@lists.infradead.org Cc: keyrings@vger.kernel.org Cc: linux-security-module@vger.kernel.org Reviewed-by:Michal Suchanek <msuchanek@suse.de> Signed-off-by:
Coiby Xu <coxu@redhat.com> Signed-off-by:
Mimi Zohar <zohar@linux.ibm.com>
Loading
Please register or sign in to comment