Re: [Linux-ima-user] [RFC][PATCH] ima: add default rule for initramfs files

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Mimi Zohar
Date: Wednesday, July 14, 2010 - 5:47 am

On Wed, 2010-07-14 at 10:34 +0200, Roberto Sassu wrote:

If your other suggestion, below, of adding fsmagic info to the
measurement list doesn't suffice, then defining a new command line
option, in addition to 'ima_tcb', shouldn't be a problem.


Ok, so this takes us back to the discussion on what should be included
in the ima-nglong template. So far we have the hash algorithm(sha1,
sha256, sha512), the hash digest, filename, uid/gid, and LSM obj/subj
labels.  We can add the fsmagic after the uid/gid.  Before upstreaming
the template patches, is there anything else?  (Remember, the more info
we add, the larger the measurement list becomes, so we shouldn't add
anything superfluously.)
    

A 'controlled environment' might exist for some device types, but not
for others.


Extending the ima-nglong template to include fsmagic, as Seiji
suggested, should resolve this problem.


Yes, nobody is suggesting otherwise.  If adding fsmagic doesn't suffice,
then in addition to 'ima_tcb', another command line option could be
defined which doesn't measure initramfs files.

Mimi

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC][PATCH] ima: add default rule for initramfs files, Roberto Sassu, (Tue Jul 6, 8:08 am)
Re: [Linux-ima-user] [RFC][PATCH] ima: add default rule fo ..., Mimi Zohar, (Wed Jul 14, 5:47 am)