[arch-commits] Commit in linux/trunk (config)

Jan Steffens heftig at archlinux.org
Fri Apr 16 12:28:13 UTC 2021


    Date: Friday, April 16, 2021 @ 12:28:12
  Author: heftig
Revision: 412709

Enable LOAD_UEFI_KEYS

https://bbs.archlinux.org/viewtopic.php?pid=1861193#p1861193

Requested by Foxboron.

Modified:
  linux/trunk/config

--------+
 config |   12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

Modified: config
===================================================================
--- config	2021-04-16 11:05:24 UTC (rev 412708)
+++ config	2021-04-16 12:28:12 UTC (rev 412709)
@@ -9628,8 +9628,17 @@
 CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y
 # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set
 # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set
-# CONFIG_INTEGRITY is not set
+CONFIG_INTEGRITY=y
+CONFIG_INTEGRITY_SIGNATURE=y
+CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
+CONFIG_INTEGRITY_TRUSTED_KEYRING=y
+CONFIG_INTEGRITY_PLATFORM_KEYRING=y
+CONFIG_LOAD_UEFI_KEYS=y
+CONFIG_INTEGRITY_AUDIT=y
+# CONFIG_IMA is not set
+# CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY is not set
 # CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set
+# CONFIG_EVM is not set
 # CONFIG_DEFAULT_SECURITY_SELINUX is not set
 # CONFIG_DEFAULT_SECURITY_SMACK is not set
 # CONFIG_DEFAULT_SECURITY_TOMOYO is not set
@@ -10034,6 +10043,7 @@
 CONFIG_CLZ_TAB=y
 CONFIG_IRQ_POLL=y
 CONFIG_MPILIB=y
+CONFIG_SIGNATURE=y
 CONFIG_DIMLIB=y
 CONFIG_OID_REGISTRY=y
 CONFIG_UCS2_STRING=y



More information about the arch-commits mailing list