diff --git a/.gitignore b/.gitignore index d1d52cf..6d559b3 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,2 @@ -/ima-evm-utils-0.6.tar.gz -/ima-evm-utils-0.9.tar.gz -/ima-evm-utils-1.0.tar.gz -/ima-evm-utils-1.1.tar.gz +/ima-evm-utils-*.tar.gz +prepare_sources_result*/ diff --git a/.packit.yaml b/.packit.yaml new file mode 100644 index 0000000..a97cb7f --- /dev/null +++ b/.packit.yaml @@ -0,0 +1,34 @@ +# See the documentation for more information: +# https://packit.dev/docs/configuration/ + +specfile_path: ima-evm-util.spec + +# add or remove files that should be synced +files_to_sync: + - .packit.yaml + +# name in upstream package repository or registry (e.g. in PyPI) +upstream_package_name: ima-evm-utils +# downstream (Fedora) RPM package name +downstream_package_name: ima-evm-utils + +jobs: + # This is triggered by https://release-monitoring.org/ + - job: pull_from_upstream + trigger: release + dist_git_branches: + - fedora-all + + # This is triggered at Fedora dist-git for creating koji build after + # PR in src.fedoraproject.org been merged. + - job: koji_build + trigger: commit + allowed_pr_authors: ["all_committers", "packit"] + dist_git_branches: + - fedora-all + + # This is triggered at Fedora messaging bus about koji build finished. + - job: bodhi_update + trigger: commit + allowed_builders: ["all_committers", "packit"] + dist_git_branches: diff --git a/docbook-xsl-path.patch b/docbook-xsl-path.patch deleted file mode 100644 index e4ee8e5..0000000 --- a/docbook-xsl-path.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -urNp ima-evm-utils-1.0-orig/Makefile.am ima-evm-utils-1.0/Makefile.am ---- ima-evm-utils-1.0-orig/Makefile.am 2015-07-30 15:28:53.000000000 -0300 -+++ ima-evm-utils-1.0/Makefile.am 2017-11-20 16:20:04.245591165 -0200 -@@ -24,7 +24,7 @@ rpm: $(tarname) - rpmbuild -ba --nodeps $(SPEC) - - # requires asciidoc, xslproc, docbook-xsl --MANPAGE_DOCBOOK_XSL = /usr/share/xml/docbook/stylesheet/docbook-xsl/manpages/docbook.xsl -+MANPAGE_DOCBOOK_XSL = /usr/share/sgml/docbook/xsl-stylesheets/manpages/docbook.xsl - - evmctl.1.html: README - @asciidoc -o $@ $< diff --git a/dracut-98-integrity.conf b/dracut-98-integrity.conf new file mode 100644 index 0000000..0996b9a --- /dev/null +++ b/dracut-98-integrity.conf @@ -0,0 +1 @@ +add_dracutmodules+=" integrity " diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh new file mode 100755 index 0000000..f0e9dd0 --- /dev/null +++ b/ima-add-sigs.sh @@ -0,0 +1,141 @@ +#!/bin/bash +# +# This script add IMA signatures to installed RPM package files +usage() { + echo "Add IMA signatures to installed packages." + cat <reinstall_threshold (=20 by default) packages in the RPM + DB missing IMA signatures, reinstalling the packages to add IMA + signatures to the packages. By default, IMA sigatures will be obtained + from the RPM DB. However the RPM DB may not have the signatures. Dectect + this case by checking if there are >reinstall_threshold package missing + IMA signatures. + + --ima_cert + With the signing IMA cert path specified, it will also try to verify the + added IMA signature. + +EOF + exit 1 +} + +for _opt in "$@"; do + case "$_opt" in + --reinstall_threshold=*) + reinstall_threshold=${_opt#*=} + ;; + --package=*) + package=${_opt#*=} + ;; + --ima_cert=*) + ima_cert=${_opt#*=} + ;; + *) + [[ -n $1 ]] && usage + ;; + esac +done + +if [[ -z $package ]] || [[ $package == ALL ]]; then + package="--all" +fi + +abort() { + echo "$1" + exit 1 +} + +get_system_ima_key() { + source /etc/os-release + local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease') + local version_id + key_name=${name_map[$NAME]} + version_id=${VERSION_ID/.?/} + + [[ $key_name == fedora ]] && name_suffix=-ima + key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der + if [[ ! -e $key_path ]]; then + echo "Failed to get system IMA code verification key" + exit 1 + fi + + echo -n "$key_path" +} + +# Add IMA signatures from RPM database +add_from_rpm_db() { + if ! command -v setfattr &>/dev/null; then + abort "Please install attr" + fi + + if [[ -e "$ima_cert" ]]; then + verify_ima_cert=$ima_cert + else + verify_ima_cert=$(get_system_ima_key) + fi + + # use "|" as deliminator since it won't be used in a filename or signature + while IFS="|" read -r path sig; do + # [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA + # signatures. This may be a issue of rpm + if [[ "$sig" != "0"* ]]; then + continue + fi + + # Skip directory, soft links, non-existent files and vfat fs + if [[ -d "$path" || -L "$path" || ! -f "$path" || "$path" == "/boot/efi/EFI/"* ]]; then + continue + fi + + # Skip some files that are created on the fly + if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then + continue + fi + + if ! setfattr -n security.ima "$path" -v "0x$sig"; then + echo "Failed to add IMA sig for $path" + fi + + if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then + setfattr -x security.ima "$path" + # When ima_cert is set, shows the verfication result for users + [[ -e "$ima_cert" ]] && "Failed to verify $path" + continue + fi + + done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package") +} + +# Add IMA signatures by reinstalling all packages +add_by_reinstall() { + [[ $package == "--all" ]] && package='*' + dnf reinstall "$package" -yq >/dev/null +} + +if [[ -z $reinstall_threshold ]]; then + if [[ $package == "--all" ]]; then + reinstall_threshold=20 + else + if ! rpm -q --quiet "$package"; then + dnf install "$package" -yq >/dev/null + exit 0 + fi + reinstall_threshold=1 + fi +fi + +unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$") + +if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then + add_by_reinstall +else + add_from_rpm_db +fi diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 4754e51..29915ec 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -1,22 +1,47 @@ +# If the soname gets bumped we need to ship a compat library to be able +# to bootstrap and rebuild rpm else we end up with chicken and egg problem. +%global bootstrap 0 + +%if 0%{bootstrap} +%global compat_soversion 4 +%endif + +Name: ima-evm-utils +Version: 1.6.2 +Release: 7%{?dist} Summary: IMA/EVM support utilities -Name: ima-evm-utils -Version: 1.1 -Release: 4%{?dist} -License: GPLv2 -Url: http://linux-ima.sourceforge.net/ -Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz +License: GPL-2.0-or-later +Url: https://github.com/linux-integrity/ +Source0: %{url}/ima-evm-utils/releases/download/v%{version}/%{name}-%{version}.tar.gz + +# IMA setup tools +Source2: dracut-98-integrity.conf +Source3: ima-add-sigs.sh +Source4: ima-setup.sh +Source100: policy-01-appraise-executable-and-lib-signatures +Source101: policy-02-keylime-remote-attestation +Source200: policy_list + +%if 0%{bootstrap} +# compat source and patches +Source10: ima-evm-utils-1.5.tar.gz +BuildRequires: openssl-devel-engine +%endif + +BuildRequires: asciidoc BuildRequires: autoconf BuildRequires: automake -BuildRequires: libtool -BuildRequires: m4 -BuildRequires: asciidoc -BuildRequires: libxslt -BuildRequires: openssl-devel +BuildRequires: gcc BuildRequires: keyutils-libs-devel -# upstream already solved both issues addressed by patch1 and 2, but it's -# still queued for next release -Patch1: docbook-xsl-path.patch -Patch2: remove-libattr-dependency.patch +BuildRequires: libtool +BuildRequires: libxslt +BuildRequires: make +BuildRequires: openssl-devel +BuildRequires: tpm2-tss-devel +Requires: %{name}-libs = %{version}-%{release} +Requires: rpm-plugin-ima +Requires: keyutils +Requires: attr %description The Trusted Computing Group(TCG) run-time Integrity Measurement Architecture @@ -26,42 +51,229 @@ systems extended attributes. The Extended Verification Module (EVM) prevents unauthorized changes to these extended attributes on the file system. ima-evm-utils is used to prepare the file system for these extended attributes. +%package libs +Summary: Libraries for %{name} +License: LGPL-2.0-or-later + +# to avoid ima-evm-utils and rpm-plugin-ima being installed on upgrade +# to Fedora 41 - https://bugzilla.redhat.com/show_bug.cgi?id=2319827 +Obsoletes: ima-evm-utils < 1.6 + +%description libs +This package contains the libraries for applications to use +ima-evm-utils functionality. + %package devel Summary: Development files for %{name} +Requires: %{name} = %{version}-%{release} +Requires: %{name}-libs = %{version}-%{release} %description devel This package provides the header files for %{name} %prep -%setup -q -%patch1 -p1 -%patch2 -p1 +%autosetup -p1 + +%if 0%{bootstrap} +mkdir compat/ +pushd compat/ +tar -zxf %{SOURCE10} --strip-components=1 +popd +%endif %build -mkdir -p m4 -autoreconf -f -i -%configure --disable-static -make %{?_smp_mflags} +autoreconf -vif +%configure --disable-static --disable-engine +%make_build + +%if 0%{bootstrap} +pushd compat/ +autoreconf -vif +%configure --disable-static --disable-engine +%make_build +popd +%endif %install -make DESTDIR=%{buildroot} install -find %{buildroot}%{_libdir} -type f -name "*.la" -print -delete +%make_install +find %{buildroot} -type f -name "*.la" -delete + +%if 0%{bootstrap} +pushd compat/src/.libs/ +install -p libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 +ln -s -f %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion} +popd +%endif %ldconfig_scriptlets -%files devel -%{_pkgdocdir}/*.sh -%{_includedir}/* -%{_libdir}/libimaevm.so +# IMA setup tools +install -D -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_datadir}/ima/dracut-98-integrity.conf + +mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/ima/policies +while IFS= read -r policy_file +do + install -m 644 %{_sourcedir}/policy-"$policy_file" $RPM_BUILD_ROOT%{_datadir}/ima/policies/"$policy_file" +done < %{SOURCE200} + +install -D %{SOURCE3} $RPM_BUILD_ROOT%{_bindir}/ima-add-sigs +install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup %files -%doc ChangeLog README AUTHORS -%license COPYING -%{_bindir}/* -%{_libdir}/libimaevm.so.* -%{_mandir}/man1/* +%license LICENSES.txt COPYING +%doc NEWS README AUTHORS +%{_bindir}/evmctl +%{_mandir}/man1/evmctl* + +# IMA setup tools +%{_datadir}/ima/policies +%{_datadir}/ima/dracut-98-integrity.conf +%{_bindir}/ima-add-sigs +%{_bindir}/ima-setup + +%files libs +%license LICENSES.txt COPYING.LGPL +# if you need to bump the soname version, coordinate with dependent packages +%{_libdir}/libimaevm.so.5* +%if 0%{bootstrap} +%{_libdir}/libimaevm.so.%{compat_soversion}* +%endif + +%files devel +%{_pkgdocdir}/*.sh +%{_includedir}/imaevm.h +%{_libdir}/libimaevm.so %changelog +* Thu Oct 16 2025 Coiby Xu - 1.6.2-7 +- ima-add-sigs: Use RSAHEADER to tell if a package has been signed + +* Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Mon Mar 03 2025 Coiby Xu - 1.6.2-5 +- release 1.6.2-5 + +* Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Thu Oct 31 2024 Coiby Xu - 1.6.2-3 +- Skip unsupported file systems for sample appraisal rule + +* Fri Oct 18 2024 Adam Williamson - 1.6.2-2 +- ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827 + +* Sat Aug 31 2024 Peter Robinson - 1.6.2-1 +- Update to 1.6.2 + +* Fri Aug 30 2024 Peter Robinson - 1.6.1-2 +- Fix sign_hash when built without openssl engine support (rhbz#2297927) + +* Thu Aug 29 2024 Peter Robinson - 1.6.1-1 +- Update to 1.6.1 +- Update project URLs + +* Thu Jul 18 2024 Fedora Release Engineering - 1.6-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Thu Jul 04 2024 Peter Robinson - 1.6-1 +- Update to 1.6 + +* Wed Jul 03 2024 Peter Robinson - 1.6-0 +- Bootstrap 1.6 +- Update license for new details +- Spec file updates + +* Thu Jun 06 2024 Coiby Xu - 1.5-5 +- add ima-evm-utils-libs subpackage (rpm-sign-libs can depend on ima-evm-utils-libs instead) +- add some IMA setup tools + +* Wed Jan 24 2024 Fedora Release Engineering - 1.5-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jan 20 2024 Fedora Release Engineering - 1.5-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Thu Jul 20 2023 Fedora Release Engineering - 1.5-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Jun 08 2023 Peter Robinson - 1.5-1 +- Disable bootstrap + +* Wed Jun 07 2023 Peter Robinson - 1.5-0.1 +- Update to 1.5 +- Streamline bootstrap process a little +- Bootstrap mode +- Update download URL + +* Thu Jan 19 2023 Fedora Release Engineering - 1.4-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Thu Jul 21 2022 Fedora Release Engineering - 1.4-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Thu Jan 20 2022 Fedora Release Engineering - 1.4-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Thu Jan 20 2022 Björn Esser - 1.4-4 +- Build without compat bootstrap sub package + +* Thu Jan 20 2022 Björn Esser - 1.4-3 +- Build with compat bootstrap sub package + +* Tue Jan 18 2022 Peter Robinson - 1.4-2 +- Add compat bootstrap sub package + +* Mon Nov 08 2021 Peter Robinson - 1.4-1 +- Update to 1.4 + +* Tue Sep 14 2021 Sahana Prasad - 1.3.2-4 +- Rebuilt with OpenSSL 3.0.0 + +* Thu Jul 22 2021 Fedora Release Engineering - 1.3.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Tue Jan 26 2021 Fedora Release Engineering - 1.3.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Wed Oct 28 2020 Bruno Meneguele - 1.3.2-1 +- Rebase to new upstream v1.3.2 minor release + +* Tue Aug 11 2020 Bruno Meneguele - 1.3.1-1 +- Rebase to new upstream v1.3.1 minor release + +* Tue Jul 28 2020 Fedora Release Engineering - 1.3-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Sun Jul 26 2020 Peter Robinson - 1.3-2 +- Fix devel deps + +* Sun Jul 26 2020 Peter Robinson - 1.3-1 +- Update to 1.3 +- Use tpm2-tss instead of tss2 +- Minor spec cleanups + +* Mon Jul 13 2020 Tom Stellard - 1.2.1-4 +- Use make macros +- https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro + +* Wed Jan 29 2020 Fedora Release Engineering - 1.2.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Wed Jul 31 2019 Bruno E. O. Meneguele - 1.2.1-2 +- Add pull request to correct lib soname version, wich was bumped to 1.0.0 + +* Wed Jul 31 2019 Bruno E. O. Meneguele - 1.2.1-1 +- Rebase to upstream v1.2.1 +- Remove both patches that were already solved in upstream version +- Add runtime dependency of tss2 to retrieve PCR bank data from TPM2.0 + +* Thu Jul 25 2019 Fedora Release Engineering - 1.1-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Fri Feb 01 2019 Fedora Release Engineering - 1.1-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + * Fri Jul 20 2018 Bruno E. O. Meneguele - 1.1-4 - Add patch to remove dependency from libattr-devel package diff --git a/ima-setup.sh b/ima-setup.sh new file mode 100755 index 0000000..1450c0a --- /dev/null +++ b/ima-setup.sh @@ -0,0 +1,134 @@ +#!/bin/bash +# +# This script helps set up IMA. +# +IMA_SYSTEMD_POLICY=/etc/ima/ima-policy +IMA_POLICY_SYSFS=/sys/kernel/security/ima/policy + +usage() { + echo "Set up IMA." + cat <reinstall_threshold packages in the RPM DB missing IMA + signatures, reinstalling the packages to add IMA signatures to the + packages. By default, IMA sigatures will be obtained from the RPM DB. + However the RPM DB may not have the signatures. Dectect this case by + checking if there are >reinstall_threshold package missing IMA + signatures. + +EOF + exit 1 +} + +for _opt in "$@"; do + case "$_opt" in + --policy=*) + ima_policy_path=${_opt#*=} + if [[ ! -e $ima_policy_path ]]; then + echo "$ima_policy_path doesn't exist" + exit 1 + fi + ;; + --reinstall_threshold=*) + reinstall_threshold=${_opt#*=} + ;; + *) + usage + ;; + esac +done + +if [[ $# -eq 0 ]]; then + usage +fi + +# Add IMA signatures +if test -f /run/ostree-booted; then + echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process." +else + echo "Adding IMA signatures to installed package files" + if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then + echo "Failed to add IMA signatures, abort" + exit 1 + fi +fi + +load_ima_keys() { + local _key_loaded + + if line=$(keyctl describe %keyring:.ima); then + _ima_id=${line%%:*} + else + echo "Failed to get ID of the .ima keyring" + exit 1 + fi + + for i in /etc/keys/ima/*; do + if [ ! -f "${i}" ]; then + echo "No IMA key exist" + exit 1 + fi + + if ! evmctl import "${i}" "${_ima_id}" &>/dev/null; then + echo "Failed to load IMA key ${i}" + else + _key_loaded=yes + fi + done + + if [[ $_key_loaded != yes ]]; then + echo "No IMA key loaded" + exit 1 + fi +} + +load_ima_policy() { + local ima_policy_path + + ima_policy_path=$1 + + if ! test -f "$ima_policy_path"; then + echo "$ima_policy_path doesn't exist" + return 1 + fi + if ! echo "$ima_policy_path" >"$IMA_POLICY_SYSFS"; then + echo "$ima_policy_path can't be loaded" + return 1 + fi + # Let systemd load the IMA policy which will load LSM rules first so IMA + # policy containing rules like "appraise obj_type=ifconfig_exec_t" can be + # loaded + [[ -e /etc/ima ]] || mkdir -p /etc/ima/ + if ! cp --preserve=xattr "$ima_policy_path" "$IMA_SYSTEMD_POLICY"; then + echo "Failed to copy $ima_policy_path to $IMA_SYSTEMD_POLICY" + return 1 + fi +} + +echo "Loading IMA keys" +load_ima_keys + +# Include the dracut integrity module to load the IMA keys and policy +# automatically when there is a system reboot +if ! lsinitrd --mod | grep -q integrity; then + cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf + echo "Regenerating all initramfs images to include the dracut integrity module" + if ! dracut -f --regenerate-all; then + echo "Failed to Regenerate all initramfs images" + exit 1 + fi + [[ $(uname -m) == s390x ]] && zipl &> /dev/null +fi + +if ! load_ima_policy "$ima_policy_path"; then + echo "Failed to load IMA policy $ima_policy_path!" + exit 1 +fi diff --git a/openssl1-1-interface.patch b/openssl1-1-interface.patch deleted file mode 100644 index e00fb2f..0000000 --- a/openssl1-1-interface.patch +++ /dev/null @@ -1,224 +0,0 @@ -diff -urNp ima-evm-utils-1.0-orig/src/libimaevm.c ima-evm-utils-1.0/src/libimaevm.c ---- ima-evm-utils-1.0-orig/src/libimaevm.c 2015-07-30 15:28:53.000000000 -0300 -+++ ima-evm-utils-1.0/src/libimaevm.c 2017-12-01 12:01:28.008705290 -0200 -@@ -269,7 +269,7 @@ int ima_calc_hash(const char *file, uint - { - const EVP_MD *md; - struct stat st; -- EVP_MD_CTX ctx; -+ EVP_MD_CTX *ctx; - unsigned int mdlen; - int err; - -@@ -286,25 +286,30 @@ int ima_calc_hash(const char *file, uint - return 1; - } - -- err = EVP_DigestInit(&ctx, md); -+ ctx = EVP_MD_CTX_new(); -+ if (!ctx) { -+ log_err("EVP_MD_CTX_new() failed\n"); -+ return 1; -+ } -+ err = EVP_DigestInit_ex(ctx, md, NULL); - if (!err) { -- log_err("EVP_DigestInit() failed\n"); -+ log_err("EVP_DigestInit_ex() failed\n"); - return 1; - } - - switch (st.st_mode & S_IFMT) { - case S_IFREG: -- err = add_file_hash(file, &ctx); -+ err = add_file_hash(file, ctx); - break; - case S_IFDIR: -- err = add_dir_hash(file, &ctx); -+ err = add_dir_hash(file, ctx); - break; - case S_IFLNK: -- err = add_link_hash(file, &ctx); -+ err = add_link_hash(file, ctx); - break; - case S_IFIFO: case S_IFSOCK: - case S_IFCHR: case S_IFBLK: -- err = add_dev_hash(&st, &ctx); -+ err = add_dev_hash(&st, ctx); - break; - default: - log_errno("Unsupported file type"); -@@ -314,11 +319,12 @@ int ima_calc_hash(const char *file, uint - if (err) - return err; - -- err = EVP_DigestFinal(&ctx, hash, &mdlen); -+ err = EVP_DigestFinal_ex(ctx, hash, &mdlen); - if (!err) { -- log_err("EVP_DigestFinal() failed\n"); -+ log_err("EVP_DigestFinal_ex() failed\n"); - return 1; - } -+ EVP_MD_CTX_free(ctx); - - return mdlen; - } -@@ -547,6 +553,7 @@ int key2bin(RSA *key, unsigned char *pub - { - int len, b, offset = 0; - struct pubkey_hdr *pkh = (struct pubkey_hdr *)pub; -+ const BIGNUM *n, *e; - - /* add key header */ - pkh->version = 1; -@@ -556,18 +563,19 @@ int key2bin(RSA *key, unsigned char *pub - - offset += sizeof(*pkh); - -- len = BN_num_bytes(key->n); -- b = BN_num_bits(key->n); -+ RSA_get0_key(key, &n, &e, NULL); -+ len = BN_num_bytes(n); -+ b = BN_num_bits(n); - pub[offset++] = b >> 8; - pub[offset++] = b & 0xff; -- BN_bn2bin(key->n, &pub[offset]); -+ BN_bn2bin(n, &pub[offset]); - offset += len; - -- len = BN_num_bytes(key->e); -- b = BN_num_bits(key->e); -+ len = BN_num_bytes(e); -+ b = BN_num_bits(e); - pub[offset++] = b >> 8; - pub[offset++] = b & 0xff; -- BN_bn2bin(key->e, &pub[offset]); -+ BN_bn2bin(e, &pub[offset]); - offset += len; - - return offset; - -diff -urNp ima-evm-utils-1.0-orig/src/evmctl.c ima-evm-utils-1.0/src/evmctl.c ---- ima-evm-utils-1.0-orig/src/evmctl.c 2015-07-30 15:28:53.000000000 -0300 -+++ ima-evm-utils-1.0/src/evmctl.c 2017-12-01 12:00:39.683306265 -0200 -@@ -305,7 +305,7 @@ static int calc_evm_hash(const char *fil - struct stat st; - int err; - uint32_t generation = 0; -- EVP_MD_CTX ctx; -+ EVP_MD_CTX *ctx; - unsigned int mdlen; - char **xattrname; - char xattr_value[1024]; -@@ -345,9 +345,14 @@ static int calc_evm_hash(const char *fil - return -1; - } - -- err = EVP_DigestInit(&ctx, EVP_sha1()); -+ ctx = EVP_MD_CTX_new(); -+ if (!ctx) { -+ log_err("EVP_MD_CTX_new() failed\n"); -+ return 1; -+ } -+ err = EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); - if (!err) { -- log_err("EVP_DigestInit() failed\n"); -+ log_err("EVP_DigestInit_ex() failed\n"); - return 1; - } - -@@ -364,7 +369,7 @@ static int calc_evm_hash(const char *fil - /*log_debug("name: %s, value: %s, size: %d\n", *xattrname, xattr_value, err);*/ - log_info("name: %s, size: %d\n", *xattrname, err); - log_debug_dump(xattr_value, err); -- err = EVP_DigestUpdate(&ctx, xattr_value, err); -+ err = EVP_DigestUpdate(ctx, xattr_value, err); - if (!err) { - log_err("EVP_DigestUpdate() failed\n"); - return 1; -@@ -412,7 +417,7 @@ static int calc_evm_hash(const char *fil - log_debug("hmac_misc (%d): ", hmac_size); - log_debug_dump(&hmac_misc, hmac_size); - -- err = EVP_DigestUpdate(&ctx, &hmac_misc, hmac_size); -+ err = EVP_DigestUpdate(ctx, &hmac_misc, hmac_size); - if (!err) { - log_err("EVP_DigestUpdate() failed\n"); - return 1; -@@ -423,18 +428,19 @@ static int calc_evm_hash(const char *fil - if (err) - return -1; - -- err = EVP_DigestUpdate(&ctx, (const unsigned char *)uuid, sizeof(uuid)); -+ err = EVP_DigestUpdate(ctx, (const unsigned char *)uuid, sizeof(uuid)); - if (!err) { - log_err("EVP_DigestUpdate() failed\n"); - return 1; - } - } - -- err = EVP_DigestFinal(&ctx, hash, &mdlen); -+ err = EVP_DigestFinal_ex(ctx, hash, &mdlen); - if (!err) { - log_err("EVP_DigestFinal() failed\n"); - return 1; - } -+ EVP_MD_CTX_free(ctx); - - return mdlen; - } -@@ -844,7 +850,7 @@ static int calc_evm_hmac(const char *fil - struct stat st; - int err = -1; - uint32_t generation = 0; -- HMAC_CTX ctx; -+ HMAC_CTX *ctx; - unsigned int mdlen; - char **xattrname; - unsigned char xattr_value[1024]; -@@ -900,10 +906,15 @@ static int calc_evm_hmac(const char *fil - goto out; - } - -- err = !HMAC_Init(&ctx, evmkey, sizeof(evmkey), EVP_sha1()); -+ ctx = HMAC_CTX_new(); -+ if (!ctx) { -+ log_err("HMAC_MD_CTX_new() failed\n"); -+ goto out; -+ } -+ err = !HMAC_Init_ex(ctx, evmkey, sizeof(evmkey), EVP_sha1(), NULL); - if (err) { - log_err("HMAC_Init() failed\n"); -- goto out; -+ goto out_ctx_cleanup; - } - - for (xattrname = evm_config_xattrnames; *xattrname != NULL; xattrname++) { -@@ -919,7 +930,7 @@ static int calc_evm_hmac(const char *fil - /*log_debug("name: %s, value: %s, size: %d\n", *xattrname, xattr_value, err);*/ - log_info("name: %s, size: %d\n", *xattrname, err); - log_debug_dump(xattr_value, err); -- err = !HMAC_Update(&ctx, xattr_value, err); -+ err = !HMAC_Update(ctx, xattr_value, err); - if (err) { - log_err("HMAC_Update() failed\n"); - goto out_ctx_cleanup; -@@ -960,16 +971,16 @@ static int calc_evm_hmac(const char *fil - log_debug("hmac_misc (%d): ", hmac_size); - log_debug_dump(&hmac_misc, hmac_size); - -- err = !HMAC_Update(&ctx, (const unsigned char *)&hmac_misc, hmac_size); -+ err = !HMAC_Update(ctx, (const unsigned char *)&hmac_misc, hmac_size); - if (err) { - log_err("HMAC_Update() failed\n"); - goto out_ctx_cleanup; - } -- err = !HMAC_Final(&ctx, hash, &mdlen); -+ err = !HMAC_Final(ctx, hash, &mdlen); - if (err) - log_err("HMAC_Final() failed\n"); - out_ctx_cleanup: -- HMAC_CTX_cleanup(&ctx); -+ HMAC_CTX_free(ctx); - out: - free(key); - return err ?: mdlen; diff --git a/policy-01-appraise-executable-and-lib-signatures b/policy-01-appraise-executable-and-lib-signatures new file mode 100644 index 0000000..53feed5 --- /dev/null +++ b/policy-01-appraise-executable-and-lib-signatures @@ -0,0 +1,28 @@ +# Skip some unsupported filesystems +# This list of the filesystems can be found on +# https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy +# PROC_SUPER_MAGIC +dont_appraise fsmagic=0x9fa0 +# SYSFS_MAGIC +dont_appraise fsmagic=0x62656572 +# DEBUGFS_MAGIC +dont_appraise fsmagic=0x64626720 +# TMPFS_MAGIC +dont_appraise fsmagic=0x01021994 +# RAMFS_MAGIC +dont_appraise fsmagic=0x858458f6 +# DEVPTS_SUPER_MAGIC +dont_appraise fsmagic=0x1cd1 +# BINFMTFS_MAGIC +dont_appraise fsmagic=0x42494e4d +# SECURITYFS_MAGIC +dont_appraise fsmagic=0x73636673 +# SELINUX_MAGIC +dont_appraise fsmagic=0xf97cff8c +# CGROUP_SUPER_MAGIC +dont_appraise fsmagic=0x27e0eb +# NSFS_MAGIC +dont_appraise fsmagic=0x6e736673 + +appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig +appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy-02-keylime-remote-attestation b/policy-02-keylime-remote-attestation new file mode 100644 index 0000000..5210734 --- /dev/null +++ b/policy-02-keylime-remote-attestation @@ -0,0 +1,37 @@ +# PROC_SUPER_MAGIC +dont_measure fsmagic=0x9fa0 +# SYSFS_MAGIC +dont_measure fsmagic=0x62656572 +# DEBUGFS_MAGIC +dont_measure fsmagic=0x64626720 +# TMPFS_MAGIC +dont_measure fsmagic=0x01021994 +# DEVPTS_SUPER_MAGIC +dont_measure fsmagic=0x1cd1 +# BINFMTFS_MAGIC +dont_measure fsmagic=0x42494e4d +# SECURITYFS_MAGIC +dont_measure fsmagic=0x73636673 +# SELINUX_MAGIC +dont_measure fsmagic=0xf97cff8c +# SMACK_MAGIC +dont_measure fsmagic=0x43415d53 +# CGROUP_SUPER_MAGIC +dont_measure fsmagic=0x27e0eb +# CGROUP2_SUPER_MAGIC +dont_measure fsmagic=0x63677270 +# NSFS_MAGIC +dont_measure fsmagic=0x6e736673 +# EFIVARFS_MAGIC +dont_measure fsmagic=0xde5e81e4 +# OVERLAYFS_MAGIC +# when containers are used we almost always want to ignore them +dont_measure fsmagic=0x794c7630 + + +# Measure and log keys loaded onto the .ima keyring +measure func=KEY_CHECK keyrings=.ima +# Measure and log executables +measure func=BPRM_CHECK +# Measure and log shared libraries +measure func=FILE_MMAP mask=MAY_EXEC diff --git a/policy_list b/policy_list new file mode 100644 index 0000000..af81a74 --- /dev/null +++ b/policy_list @@ -0,0 +1,2 @@ +01-appraise-executable-and-lib-signatures +02-keylime-remote-attestation diff --git a/remove-libattr-dependency.patch b/remove-libattr-dependency.patch deleted file mode 100644 index 0c7a5a0..0000000 --- a/remove-libattr-dependency.patch +++ /dev/null @@ -1,29 +0,0 @@ -diff --git a/configure.ac b/configure.ac -index 0497eb7..a5b4288 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -30,7 +30,7 @@ AC_SUBST(OPENSSL_LIBS) - AC_CHECK_HEADER(unistd.h) - AC_CHECK_HEADERS(openssl/conf.h) - --AC_CHECK_HEADERS(attr/xattr.h, , [AC_MSG_ERROR([attr/xattr.h header not found. You need the libattr development package.])]) -+AC_CHECK_HEADERS(sys/xattr.h, , [AC_MSG_ERROR([sys/xattr.h header not found. You need the c-library development package.])]) - AC_CHECK_HEADERS(keyutils.h, , [AC_MSG_ERROR([keyutils.h header not found. You need the libkeyutils development package.])]) - - #debug support - yes for a while -diff --git a/src/evmctl.c b/src/evmctl.c -index 2ffee78..3fbcd33 100644 ---- a/src/evmctl.c -+++ b/src/evmctl.c -@@ -49,7 +49,7 @@ - #include - #include - #include --#include -+#include - #include - #include - #include --- -2.14.4 - diff --git a/sources b/sources index baf9168..f312ac6 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (ima-evm-utils-1.1.tar.gz) = fc7efc890812233db888eef210dc4357bee838b56fd95efd9a9e141d684b0b354670a3c053dd93a94a1402dd826074d4a83a4637c8e6c1d90ead3132354a5776 +SHA512 (ima-evm-utils-1.6.2.tar.gz) = dfd82ba7c48c14fd31d687214a2b0cfcf269bdea42d4a0ebc872a72205f880c509ed5c5cd55dec7e94444e6f3bdc3c071ec6c2e3eba1e6579edb8ef11aa158a1