Skip to content

Commit e864d02

Browse files
kewu1992uudiin
authored andcommitted
modsign: use all trusted keys to verify module signature
commit e84cd7e upstream Make mod_verify_sig to use all trusted keys. This allows keys in secondary_trusted_keys to be used to verify PKCS#7 signature on a kernel module. Signed-off-by: Ke Wu <mikewu@google.com> Signed-off-by: Jessica Yu <jeyu@kernel.org> Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com> Reviewed-by: Jia Zhang <zhang.jia@linux.alibaba.com>
1 parent af166a8 commit e864d02

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

kernel/module_signing.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,7 @@ int mod_verify_sig(const void *mod, struct load_info *info)
8383
}
8484

8585
return verify_pkcs7_signature(mod, modlen, mod + modlen, sig_len,
86-
NULL, VERIFYING_MODULE_SIGNATURE,
86+
VERIFY_USE_SECONDARY_KEYRING,
87+
VERIFYING_MODULE_SIGNATURE,
8788
NULL, NULL);
8889
}

0 commit comments

Comments
 (0)