IMA: define a builtin critical data measurement policy
authorLakshmi Ramasubramanian <nramas@linux.microsoft.com>
Fri, 8 Jan 2021 04:07:07 +0000 (20:07 -0800)
committerMimi Zohar <zohar@linux.ibm.com>
Fri, 15 Jan 2021 04:41:43 +0000 (23:41 -0500)
commit03cee168366621db85000cec47f5cefdb83e049b
tree8354f0f679bc9e85a986b26d803bfc9da0e5b9f8
parent9f5d7d23cc5ec61a92076b73665fcb9aaa5bb5a0
IMA: define a builtin critical data measurement policy

Define a new critical data builtin policy to allow measuring
early kernel integrity critical data before a custom IMA policy
is loaded.

Update the documentation on kernel parameters to document
the new critical data builtin policy.

Signed-off-by: Lakshmi Ramasubramanian <nramas@linux.microsoft.com>
Reviewed-by: Tyler Hicks <tyhicks@linux.microsoft.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Documentation/admin-guide/kernel-parameters.txt
security/integrity/ima/ima_policy.c