Compare commits

...
Sign in to create a new pull request.

81 commits

Author SHA1 Message Date
Coiby Xu
667e783b37 Fix a typo in changelog
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 12:25:09 +08:00
Coiby Xu
3d7171c676 Release 1.6.2-7
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 11:53:12 +08:00
Coiby Xu
7e1ffed77c Allow packit to make and propose a build
Currently, only users with commit access to the dist-git repo can make
and propose a build. But packit doesn't have commit access to the repo.
So explicitly allow packit to do make and propose a build.

Fixes: e962d0c ("Use packit to automate ima-evm-utils releasing")
Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-27 11:53:12 +08:00
Coiby Xu
47853f2cf6 Use RSAHEADER to tell if a package has been signed
Packages now use RPM v4 signature %{RSAHEADER}. %{SIGPGP} is the name
of the RPM v3 header+payload signature and can't be used to tell if
a package has been signed,

    # uname -r
    6.16.10-200.fc42.x86_64
    # rpm -q --queryformat "%{SIGPGP:pgpsig}\n" --all|grep -c "^(none)$"
    586
    # rpm -q --queryformat "%{RSAHEADER}\n" --all|grep -c "^(none)$"
    5

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-10-16 17:35:31 +08:00
Coiby Xu
73f30b71db Merge #10 ima-add-sigs: Verify added IMA signature in case the file gets changed 2025-07-31 01:08:04 +00:00
Coiby Xu
aeb208fd06 Merge #9 ima-setup: rebuild all initramfs images to include the integrity dracut module 2025-07-28 01:31:56 +00:00
Coiby Xu
6f19220bcc Fix shellcheck warning and typos
Fix the following shellcheck warning,
    In ima-add-sigs.sh line 135:
    unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{SIGPGP:pgpsig}\n" "$package" | grep "^(none)$" | wc -l)
                                                                                     ^-------------^ SC2126 (style): Consider using 'grep -c' instead of 'grep|wc -l'.
Also fix two typos.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-07-25 09:27:54 +08:00
Coiby Xu
48d137ffe5 ima-add-sigs: Verify added IMA signature in case the file gets changed
Resolves: https://issues.redhat.com/browse/RHEL-100320

Some IMA signatures from the RPM database may fail the verification
because they can be changed. For examples, the following files on F41
can't pass IMA signature verification,

    /usr/lib64/gconv/gconv-modules.cache
    /boot/grub2/grubenv
    /var/lib/selinux/targeted/active/commit_num
    /var/lib/selinux/targeted/active/file_contexts
    /etc/ssh/sshd_config
    /etc/yum.repos.d/fedora-updates.repo
    /etc/yum.repos.d/fedora.repo
    /etc/group
    /etc/gshadow

The kernel ima=fix mode won't generate IMA hash reference value for
files with IMA signature. As a result, users can be denied the access to
some files. So remove security.ima if a file fail the verification.
2025-07-25 09:26:55 +08:00
Coiby Xu
ac36e54bee ima-setup: rebuild all initramfs images to include the integrity dracut module
Resolves: https://issues.redhat.com/browse/RHEL-92638

Quoting Raju,
  ima-setup currently only rebuild the initramfs of running kernel, so
  the older kernel's(n-1 or n-2) initramfs does contain an outdated
  information or it does not contain ima module, as a result the system
  fails to boot with older kernel.

  It is always recommended to have at least 2 older kernel's kept
  installed on the system as a fallback option in case if the latest
  kernel fails to boot due to some unforeseen issue. So that we can boot
  the system with older kernel to troubleshoot the can't boot issue with
  older kernel.

Suggested-by: Raju Cheerla <rcheerla@redhat.com>
2025-07-25 09:20:41 +08:00
Fedora Release Engineering
aed78ac85f Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-24 17:36:58 +00:00
Coiby Xu
c68b187d3e Release 1.6.2-5 2025-03-03 10:12:46 +08:00
Coiby Xu
e962d0cac4 Use packit to automate ima-evm-utils releasing
Follow [1] to use packit to automate releasing ima-evm-utils. After finishing
one-time setting up, when there is a new upstream release, here's the
new process of releasing a new version in Fedora,

1. https://release-monitoring.org/ finds a new upstream and notify
   packit

2. packit: automatically create PRs to propose new release for different
   Fedora releases;  also upload new tarballs into lookaside cache.

3. Maintainer: review(, modify) and merge the PR

4. packit: create a koji build

5. packit: create a Bodhi update

So maintainers only need to do step 3 manually and all the repetitive
work can be left to packit to handle.

After the PR gets merged, two more things need to be done [2],
 - Create a Fedora mapping for the upstream project in
   https://release-monitoring.org/projects
 - Set Monitoring status on the left side at
   https://src.fedoraproject.org/rpms/ima-evm-utils to Monitoring

[1] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding
[2] https://packit.dev/docs/fedora-releases-guide/dist-git-onboarding#2-monitoring-of-the-package

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-03-03 10:12:16 +08:00
Coiby Xu
7b800d82d0 ima-setup: fix two shellcheck warnings
Fix the following two shellcheck warnings,

    In ima-setup.sh line 36:
                            echo "$policy_file doesn't exist"
                                  ^----------^ SC2154 (warning): policy_file is referenced but not assigned.

    In ima-setup.sh line 41:
                    reinstall_threshold=${_opt#*=}
                    ^-----------------^ SC2034 (warning): reinstall_threshold appears unused. Verify use (or export if used externally).

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-02-25 13:25:15 +08:00
Coiby Xu
2f1870b21a ima-setup: run zipl after building initramfs for s390x
Resovles: https://issues.redhat.com/browse/RHEL-74293

Without running zipl, the old initramfs will be booted.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2025-02-25 13:19:14 +08:00
Fedora Release Engineering
e15aa409cd Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-17 07:03:53 +00:00
Coiby Xu
083226d5ef update to 1.6.2-3 2024-10-31 15:02:33 +08:00
Coiby Xu
0e28d7448d add usage for ima-add-sigs
Also format the usage info ima-setup.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-10-31 14:13:47 +08:00
Coiby Xu
83b610d7ed Skip some file systems for appraisal
Resolves: https://issues.redhat.com/browse/RHEL-62817

When 01-appraise-exectuables-and-lib-signatures is enabled, no login
screen is available for user to log in. This happens because IMA stops
gnome-shell from creating some temp files as can been from the audit log,

    type=INTEGRITY_DATA msg=audit(1728700747.130:10235): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="/dev/shm/#3223" dev="tmpfs" ino=3223 res=0 errno=0UID="gdm" AUID="unset"
    type=INTEGRITY_DATA msg=audit(1728700747.130:10236): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="/run/user/42/#454" dev="tmpfs" ino=454 res=0 errno=0UID="gdm" AUID="unset"
    type=INTEGRITY_DATA msg=audit(1728700747.131:10237): pid=3240 uid=42 auid=4294967295 ses=4294967295 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 op=appraise_data cause=IMA-signature-required comm="gnome-shell" name="memfd:libffi" dev="tmpfs" ino=578 res=0 errno=0UID="gdm" AUID="unset"

Skip the file systems as listed in
https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy

Reported-by: Raju Cheerla <rcheerla@redhat.com>
2024-10-31 14:13:47 +08:00
Adam Williamson
a15c0930eb ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827
This should fix the problem that, on upgrade to Fedora 41,
ima-evm-utils is kept installed (even though it's likely no
longer needed, only the bits split out into ima-evm-utils-libs)
and drags in rpm-plugin-ima as a dependency. We do not want that
package installed in typical use cases, it should be opt-in only.
2024-10-19 15:10:34 -07:00
Peter Robinson
b3f1d7bf0e drop upstream patch 2024-08-31 10:55:24 +01:00
Peter Robinson
1da998f418 Update to 1.6.2 2024-08-31 10:48:53 +01:00
Peter Robinson
f21f3c2154 Fix sign_hash when built without openssl engine support (rhbz#2297927) 2024-08-30 11:26:13 +01:00
Peter Robinson
01077eea3f 1.6.1 2024-08-29 10:55:31 +01:00
Fedora Release Engineering
15e23a0944 Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-18 10:17:23 +00:00
Peter Robinson
eac85666d3 bump release 2024-07-05 13:30:10 +01:00
Peter Robinson
c7007efe32 Update to 1.6 post bootstrap 2024-07-04 15:24:13 +01:00
Peter Robinson
495b876707 Bootstrap 1.6, update licenses, spec updates 2024-07-04 15:02:01 +01:00
Coiby Xu
99360adddc Release 1.5-5
Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-06-07 22:00:38 +08:00
Coiby Xu
62f613cbb7 ima-setup: include the integrity module for the default kernel
ima-setup may run after a new kernel is installed. Detect this case by
checking if the default kernel is the running kernel.

Suggested-by: Marko Myllynen <myllynen@redhat.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-06-07 22:00:38 +08:00
Coiby Xu
141a74d96a ima-setup: Allow users to specify custom reinstall_threshold
Some users may use custom built packages and we are not sure about the
number of this type of packages. So make reinstall_threshold
configurable.

Suggested-by: Marko Myllynen <myllynen@redhat.com>
2024-06-07 22:00:38 +08:00
Coiby Xu
8980421a04 Add some IMA setup tools
Some IMA setup tools are added to ease IMA setup which will do
the following tasks,
   - add IMA signatures to installed packages files
   - load IMA keys and policy
   - enable the dracut integrity module to load IMA keys and policy
     automatically

Two IMA polices as suggested by Stefan Berger are also provided which
will be signed automatically with other package files.

Thanks to Marko Myllynen for coming up with the idea to have a tool
similar to fips-mode-setup. And thanks to Mimi Zohar and Stefan Berger
for providing the feedback!

Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-06-07 22:00:33 +08:00
Coiby Xu
166b1dccdb Add ima-evm-utils-libs subpackage
Quoting Peter,
> split out /usr/lib64/libimaevm.so.* to ima-evm-utils-libs so that for
> users that don't need IMA they just have the library and then the
> tools/utils are only installed for those that want IMA and we can add
> deps on keyutils and rpm-plugin-ima

Suggested-by: Peter Robinson <pbrobinson@gmail.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-06-06 18:09:46 +08:00
Coiby Xu
25a3b5ce1d Use SPDX licenses
Convert to SPDX license according to
https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_2,
    # license-fedora2spdx GPLv2
    GPL-2.0-only

src/{evmctl.c,libimaevm.c} use "GPL-2.0-only WITH cryptsetup-OpenSSL-exception"
and hash_info.h uses "GPL-2.0-or-later WITH Linux-syscall-note". Add
these licenses as well.

Signed-off-by: Coiby Xu <coxu@redhat.com>
2024-04-16 03:15:42 +00:00
Fedora Release Engineering
428c33916c Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-24 22:39:14 +00:00
Fedora Release Engineering
bd16779462 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-20 23:00:52 +00:00
Fedora Release Engineering
9f48b24234 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-20 07:20:43 +00:00
Peter Robinson
196c511652 Disable bootstrap 2023-06-08 10:45:50 +01:00
Peter Robinson
631781e5b2 1.5, updates for bootstrapping 2023-06-08 09:31:11 +01:00
Fedora Release Engineering
eeac9f2aed Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-19 13:05:15 +00:00
Fedora Release Engineering
c7ba98a6ec Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-21 14:35:25 +00:00
Fedora Release Engineering
558c3df69c - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-01-20 13:13:49 +00:00
Björn Esser
65d5e121c8
Build without compat bootstrap sub package
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2022-01-20 06:54:07 +01:00
Björn Esser
e87fd6c09a
Build with compat bootstrap sub package
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2022-01-20 06:36:24 +01:00
Miro Hrončok
b6235bcbb3 Actually enable compat bcond 2022-01-19 23:12:34 +01:00
Peter Robinson
3164e5a1c5 add patches for compat build 2022-01-19 15:25:39 +00:00
Peter Robinson
0602436823 Build with compatible for bootstrap 2022-01-19 15:19:26 +00:00
Peter Robinson
e3218f0188 v1.4 2021-11-08 20:52:13 +00:00
Sahana Prasad
87a9da9dc3 Rebuilt with OpenSSL 3.0.0 2021-09-14 19:04:41 +02:00
Fedora Release Engineering
fdeec277f7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-22 08:30:10 +00:00
Fedora Release Engineering
6d8b830293 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-26 14:17:04 +00:00
Tom Stellard
963df557f6 Add BuildRequires: make
https://fedoraproject.org/wiki/Changes/Remove_make_from_BuildRoot
2020-12-19 00:46:34 +00:00
Bruno Meneguele
406cc7e1e8 Rebase to new upstream v1.3.2 minor release
Resolves: BZ#1892415
Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
2020-10-28 17:57:46 -03:00
Bruno Meneguele
dad4a640db Rebase to new upstream v1.3.1 minor release
Resolves: BZ#1868019
Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
2020-08-11 11:31:20 -03:00
Fedora Release Engineering
b04b68a271 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-28 01:44:05 +00:00
Peter Robinson
845f3885b2 Fix devel deps 2020-07-26 14:07:37 +01:00
Peter Robinson
1598285d4e v1.3 2020-07-26 13:51:27 +01:00
Tom Stellard
c9a1da15a5 Use make macros
https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro
2020-07-13 20:15:21 +00:00
Fedora Release Engineering
51238b8dd6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-29 05:21:53 +00:00
Bruno E. O. Meneguele
9207116199 - Remove a leftover unused patch file
Signed-off-by: Bruno E. O. Meneguele <bmeneg@redhat.com>
2019-07-31 16:14:47 -03:00
Bruno E. O. Meneguele
44d7a51bef - Remove unused patch files
Signed-off-by: Bruno E. O. Meneguele <bmeneg@redhat.com>
2019-07-31 16:13:14 -03:00
Bruno E. O. Meneguele
a90ba569ba - Add pull request to correct lib soname version, wich was bumped to 1.0.0
Signed-off-by: Bruno E. O. Meneguele <bmeneg@redhat.com>
2019-07-31 15:32:02 -03:00
Miro Hrončok
ba5fde77a3 Avoid accidental soname version bumps 2019-07-31 20:23:06 +02:00
Bruno E. O. Meneguele
5c9e2a9130 - Rebase to upstream v1.2.1
- Remove both patches that were already solved in upstream version
- Add runtime dependency of tss2 to retrieve PCR bank data from TPM2.0

Signed-off-by: Bruno E. O. Meneguele <bmeneg@redhat.com>
2019-07-31 11:16:55 -03:00
Fedora Release Engineering
4e1e279f2b - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-25 09:26:04 +00:00
Fedora Release Engineering
709a41c76d - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-02-01 03:16:37 +00:00
Bruno E. O. Meneguele
19405d5fc4 - Add patch to remove dependency from libattr-devel package (BZ#1604365)
Signed-off-by: Bruno E. O. Meneguele <bmeneguele@gmail.com>
2018-07-20 13:08:06 -03:00
Fedora Release Engineering
be14d5b217 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-07-13 05:39:26 +00:00
Peter Robinson
f0c437d053 build on releases newer than F27 for clean upgrade path 2018-03-04 23:15:35 +00:00
Bruno E. O. Meneguele
36a11b60e9 - Remove libtool files
- Run ldconfig scriptlets after un/installing
- Add -devel subpackage to handle include files and examples
- Disable any static file in the package

Related: BZ#1548698
2018-03-02 12:04:32 -03:00
Bruno E. O. Meneguele
8ec3a62d07 - New upstream release
- Support for OpenSSL 1.1 was added directly to the source code in upstream,
  thus removing specific patch for it
- Docbook xsl stylesheet updated to a local path
2018-02-21 17:18:31 -03:00
Bruno E. O. Meneguele
846f6b26d0 - New upstream release
- Support for OpenSSL 1.1 added in upstream, thus removing specific patch for it
- Docbook xsl stylesheet updated to a local path

Signed-off-by: Bruno E. O. Meneguele <bmeneguele@gmail.com>
2018-02-16 17:15:54 -02:00
Bruno E. O. Meneguele
0738659006 - Add OpenSSL 1.1 API support for the package, avoiding the need of
compat-openssl10-devel package (BZ#1541274)
2018-02-14 14:51:21 -02:00
Fedora Release Engineering
6519dd8625 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-02-07 17:22:31 +00:00
Igor Gnatenko
45aa5845e1
Switch to %ldconfig_scriptlets
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-02 11:10:55 +01:00
Bruno E. O. Meneguele
f7d95ad7b1 - Add OpenSSL 1.1 API support for the package, avoiding the need of
compat-openssl10-devel package (BZ#1516866)
2017-12-01 18:04:04 -02:00
Bruno E. O. Meneguele
c40253b526 Adjusted docbook xsl path to match the correct stylesheet (BZ#1514985) 2017-11-20 18:42:01 -02:00
Bruno E. O. Meneguele
c1b3c4b3df - Adjusted docbook xsl path to match the correct stylesheet (BZ#1514985)
- Remove only *.la files, considering there aren't any *.a files
2017-11-20 18:31:48 -02:00
Bruno E. O. Meneguele
d9b7b2657c - New upstream release
- Add OpenSSL 1.0 compatibility package, due to issues with OpenSSL 1.1
  (BZ#1423736)
- Remove libtool files
- Run ldconfig after un/installation to update *.so files
- Add -devel subpackage to handle include files and examples
2017-09-06 15:18:30 -03:00
Bruno E. O. Meneguele
c0e3b3338e - New upstream release
- Fix OpenSSL 1.1 incompatibility issues adding OpenSSL 1.0 compat package on
  BuildRequires.

Related: BZ#1423736
2017-09-06 10:52:17 -03:00
Fedora Release Engineering
7a4997ca75 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild 2017-08-02 23:44:34 +00:00
Fedora Release Engineering
e497bcc5d6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild 2017-07-26 13:29:04 +00:00
11 changed files with 681 additions and 38 deletions

4
.gitignore vendored
View file

@ -1,2 +1,2 @@
/ima-evm-utils-0.6.tar.gz
/ima-evm-utils-0.9.tar.gz
/ima-evm-utils-*.tar.gz
prepare_sources_result*/

34
.packit.yaml Normal file
View file

@ -0,0 +1,34 @@
# See the documentation for more information:
# https://packit.dev/docs/configuration/
specfile_path: ima-evm-util.spec
# add or remove files that should be synced
files_to_sync:
- .packit.yaml
# name in upstream package repository or registry (e.g. in PyPI)
upstream_package_name: ima-evm-utils
# downstream (Fedora) RPM package name
downstream_package_name: ima-evm-utils
jobs:
# This is triggered by https://release-monitoring.org/
- job: pull_from_upstream
trigger: release
dist_git_branches:
- fedora-all
# This is triggered at Fedora dist-git for creating koji build after
# PR in src.fedoraproject.org been merged.
- job: koji_build
trigger: commit
allowed_pr_authors: ["all_committers", "packit"]
dist_git_branches:
- fedora-all
# This is triggered at Fedora messaging bus about koji build finished.
- job: bodhi_update
trigger: commit
allowed_builders: ["all_committers", "packit"]
dist_git_branches:

1
dracut-98-integrity.conf Normal file
View file

@ -0,0 +1 @@
add_dracutmodules+=" integrity "

141
ima-add-sigs.sh Executable file
View file

@ -0,0 +1,141 @@
#!/bin/bash
#
# This script add IMA signatures to installed RPM package files
usage() {
echo "Add IMA signatures to installed packages."
cat <<EOF
usage: $0 [--package=PACKAGE_NAME|ALL] [--ima_cert=IMA_CERT_PATH] [--reinstall_threshold=NUM]
--package
By default, it will add IMA sigantures to all installed package files.
Or you can provide a package name to only add IMA signature for files of
specicifed package.
--reinstall_threshold
When there are >reinstall_threshold (=20 by default) packages in the RPM
DB missing IMA signatures, reinstalling the packages to add IMA
signatures to the packages. By default, IMA sigatures will be obtained
from the RPM DB. However the RPM DB may not have the signatures. Dectect
this case by checking if there are >reinstall_threshold package missing
IMA signatures.
--ima_cert
With the signing IMA cert path specified, it will also try to verify the
added IMA signature.
EOF
exit 1
}
for _opt in "$@"; do
case "$_opt" in
--reinstall_threshold=*)
reinstall_threshold=${_opt#*=}
;;
--package=*)
package=${_opt#*=}
;;
--ima_cert=*)
ima_cert=${_opt#*=}
;;
*)
[[ -n $1 ]] && usage
;;
esac
done
if [[ -z $package ]] || [[ $package == ALL ]]; then
package="--all"
fi
abort() {
echo "$1"
exit 1
}
get_system_ima_key() {
source /etc/os-release
local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease')
local version_id
key_name=${name_map[$NAME]}
version_id=${VERSION_ID/.?/}
[[ $key_name == fedora ]] && name_suffix=-ima
key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der
if [[ ! -e $key_path ]]; then
echo "Failed to get system IMA code verification key"
exit 1
fi
echo -n "$key_path"
}
# Add IMA signatures from RPM database
add_from_rpm_db() {
if ! command -v setfattr &>/dev/null; then
abort "Please install attr"
fi
if [[ -e "$ima_cert" ]]; then
verify_ima_cert=$ima_cert
else
verify_ima_cert=$(get_system_ima_key)
fi
# use "|" as deliminator since it won't be used in a filename or signature
while IFS="|" read -r path sig; do
# [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA
# signatures. This may be a issue of rpm
if [[ "$sig" != "0"* ]]; then
continue
fi
# Skip directory, soft links, non-existent files and vfat fs
if [[ -d "$path" || -L "$path" || ! -f "$path" || "$path" == "/boot/efi/EFI/"* ]]; then
continue
fi
# Skip some files that are created on the fly
if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then
continue
fi
if ! setfattr -n security.ima "$path" -v "0x$sig"; then
echo "Failed to add IMA sig for $path"
fi
if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then
setfattr -x security.ima "$path"
# When ima_cert is set, shows the verfication result for users
[[ -e "$ima_cert" ]] && "Failed to verify $path"
continue
fi
done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package")
}
# Add IMA signatures by reinstalling all packages
add_by_reinstall() {
[[ $package == "--all" ]] && package='*'
dnf reinstall "$package" -yq >/dev/null
}
if [[ -z $reinstall_threshold ]]; then
if [[ $package == "--all" ]]; then
reinstall_threshold=20
else
if ! rpm -q --quiet "$package"; then
dnf install "$package" -yq >/dev/null
exit 0
fi
reinstall_threshold=1
fi
fi
unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$")
if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then
add_by_reinstall
else
add_from_rpm_db
fi

View file

@ -1,14 +1,47 @@
# If the soname gets bumped we need to ship a compat library to be able
# to bootstrap and rebuild rpm else we end up with chicken and egg problem.
%global bootstrap 0
%if 0%{bootstrap}
%global compat_soversion 4
%endif
Name: ima-evm-utils
Version: 1.6.2
Release: 7%{?dist}
Summary: IMA/EVM support utilities
Name: ima-evm-utils
Version: 0.9
Release: 5%{?dist}
License: GPLv2
Url: http://linux-ima.sourceforge.net/
Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz
Group: Applications/Internet
BuildRequires: autoconf automake libtool m4 asciidoc libxslt
BuildRequires: openssl-devel libattr-devel keyutils-libs-devel
Patch1: manpage.patch
License: GPL-2.0-or-later
Url: https://github.com/linux-integrity/
Source0: %{url}/ima-evm-utils/releases/download/v%{version}/%{name}-%{version}.tar.gz
# IMA setup tools
Source2: dracut-98-integrity.conf
Source3: ima-add-sigs.sh
Source4: ima-setup.sh
Source100: policy-01-appraise-executable-and-lib-signatures
Source101: policy-02-keylime-remote-attestation
Source200: policy_list
%if 0%{bootstrap}
# compat source and patches
Source10: ima-evm-utils-1.5.tar.gz
BuildRequires: openssl-devel-engine
%endif
BuildRequires: asciidoc
BuildRequires: autoconf
BuildRequires: automake
BuildRequires: gcc
BuildRequires: keyutils-libs-devel
BuildRequires: libtool
BuildRequires: libxslt
BuildRequires: make
BuildRequires: openssl-devel
BuildRequires: tpm2-tss-devel
Requires: %{name}-libs = %{version}-%{release}
Requires: rpm-plugin-ima
Requires: keyutils
Requires: attr
%description
The Trusted Computing Group(TCG) run-time Integrity Measurement Architecture
@ -18,29 +51,274 @@ systems extended attributes. The Extended Verification Module (EVM) prevents
unauthorized changes to these extended attributes on the file system.
ima-evm-utils is used to prepare the file system for these extended attributes.
%package libs
Summary: Libraries for %{name}
License: LGPL-2.0-or-later
# to avoid ima-evm-utils and rpm-plugin-ima being installed on upgrade
# to Fedora 41 - https://bugzilla.redhat.com/show_bug.cgi?id=2319827
Obsoletes: ima-evm-utils < 1.6
%description libs
This package contains the libraries for applications to use
ima-evm-utils functionality.
%package devel
Summary: Development files for %{name}
Requires: %{name} = %{version}-%{release}
Requires: %{name}-libs = %{version}-%{release}
%description devel
This package provides the header files for %{name}
%prep
%setup -q
%patch1 -p1
%autosetup -p1
%if 0%{bootstrap}
mkdir compat/
pushd compat/
tar -zxf %{SOURCE10} --strip-components=1
popd
%endif
%build
#Is running autoreconf a good idea
mkdir -p m4
autoreconf -f -i
%configure
make %{?_smp_mflags}
autoreconf -vif
%configure --disable-static --disable-engine
%make_build
%if 0%{bootstrap}
pushd compat/
autoreconf -vif
%configure --disable-static --disable-engine
%make_build
popd
%endif
%install
make DESTDIR=%{buildroot} install
%make_install
find %{buildroot} -type f -name "*.la" -delete
%if 0%{bootstrap}
pushd compat/src/.libs/
install -p libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0
ln -s -f %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}
popd
%endif
%ldconfig_scriptlets
# IMA setup tools
install -D -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_datadir}/ima/dracut-98-integrity.conf
mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/ima/policies
while IFS= read -r policy_file
do
install -m 644 %{_sourcedir}/policy-"$policy_file" $RPM_BUILD_ROOT%{_datadir}/ima/policies/"$policy_file"
done < %{SOURCE200}
install -D %{SOURCE3} $RPM_BUILD_ROOT%{_bindir}/ima-add-sigs
install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup
%files
%doc ChangeLog README AUTHORS COPYING
%{_bindir}/*
%license LICENSES.txt COPYING
%doc NEWS README AUTHORS
%{_bindir}/evmctl
%{_mandir}/man1/evmctl*
# IMA setup tools
%{_datadir}/ima/policies
%{_datadir}/ima/dracut-98-integrity.conf
%{_bindir}/ima-add-sigs
%{_bindir}/ima-setup
%files libs
%license LICENSES.txt COPYING.LGPL
# if you need to bump the soname version, coordinate with dependent packages
%{_libdir}/libimaevm.so.5*
%if 0%{bootstrap}
%{_libdir}/libimaevm.so.%{compat_soversion}*
%endif
%files devel
%{_pkgdocdir}/*.sh
%{_libdir}/libimaevm.*
%{_includedir}/*
%{_mandir}/man1/*
%{_includedir}/imaevm.h
%{_libdir}/libimaevm.so
%changelog
* Thu Oct 16 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-7
- ima-add-sigs: Use RSAHEADER to tell if a package has been signed
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Mar 03 2025 Coiby Xu <coxu@redhat.com> - 1.6.2-5
- release 1.6.2-5
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.6.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Oct 31 2024 Coiby Xu <coxu@redhat.com> - 1.6.2-3
- Skip unsupported file systems for sample appraisal rule
* Fri Oct 18 2024 Adam Williamson <awilliam@redhat.com> - 1.6.2-2
- ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827
* Sat Aug 31 2024 Peter Robinson <pbrobinson@fedoraproject.org> - 1.6.2-1
- Update to 1.6.2
* Fri Aug 30 2024 Peter Robinson <pbrobinson@fedoraproject.org> - 1.6.1-2
- Fix sign_hash when built without openssl engine support (rhbz#2297927)
* Thu Aug 29 2024 Peter Robinson <pbrobinson@fedoraproject.org> - 1.6.1-1
- Update to 1.6.1
- Update project URLs
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jul 04 2024 Peter Robinson <pbrobinson@fedoraproject.org> - 1.6-1
- Update to 1.6
* Wed Jul 03 2024 Peter Robinson <pbrobinson@fedoraproject.org> - 1.6-0
- Bootstrap 1.6
- Update license for new details
- Spec file updates
* Thu Jun 06 2024 Coiby Xu <coxu@redhat.com> - 1.5-5
- add ima-evm-utils-libs subpackage (rpm-sign-libs can depend on ima-evm-utils-libs instead)
- add some IMA setup tools
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sat Jan 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jun 08 2023 Peter Robinson <pbrobinson@fedoraproject.org> - 1.5-1
- Disable bootstrap
* Wed Jun 07 2023 Peter Robinson <pbrobinson@fedoraproject.org> - 1.5-0.1
- Update to 1.5
- Streamline bootstrap process a little
- Bootstrap mode
- Update download URL
* Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.4-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Jan 20 2022 Björn Esser <besser82@fedoraproject.org> - 1.4-4
- Build without compat bootstrap sub package
* Thu Jan 20 2022 Björn Esser <besser82@fedoraproject.org> - 1.4-3
- Build with compat bootstrap sub package
* Tue Jan 18 2022 Peter Robinson <pbrobinson@fedoraproject.org> - 1.4-2
- Add compat bootstrap sub package
* Mon Nov 08 2021 Peter Robinson <pbrobinson@fedoraproject.org> - 1.4-1
- Update to 1.4
* Tue Sep 14 2021 Sahana Prasad <sahana@redhat.com> - 1.3.2-4
- Rebuilt with OpenSSL 3.0.0
* Thu Jul 22 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.3.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.3.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Wed Oct 28 2020 Bruno Meneguele <bmeneg@redhat.com> - 1.3.2-1
- Rebase to new upstream v1.3.2 minor release
* Tue Aug 11 2020 Bruno Meneguele <bmeneg@redhat.com> - 1.3.1-1
- Rebase to new upstream v1.3.1 minor release
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Sun Jul 26 2020 Peter Robinson <pbrobinson@fedoraproject.org> - 1.3-2
- Fix devel deps
* Sun Jul 26 2020 Peter Robinson <pbrobinson@fedoraproject.org> - 1.3-1
- Update to 1.3
- Use tpm2-tss instead of tss2
- Minor spec cleanups
* Mon Jul 13 2020 Tom Stellard <tstellar@redhat.com> - 1.2.1-4
- Use make macros
- https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro
* Wed Jan 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.2.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Wed Jul 31 2019 Bruno E. O. Meneguele <bmeneg@redhat.com> - 1.2.1-2
- Add pull request to correct lib soname version, wich was bumped to 1.0.0
* Wed Jul 31 2019 Bruno E. O. Meneguele <bmeneg@redhat.com> - 1.2.1-1
- Rebase to upstream v1.2.1
- Remove both patches that were already solved in upstream version
- Add runtime dependency of tss2 to retrieve PCR bank data from TPM2.0
* Thu Jul 25 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Feb 01 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jul 20 2018 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.1-4
- Add patch to remove dependency from libattr-devel package
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Fri Mar 02 2018 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.1-2
- Remove libtool files
- Run ldconfig scriptlets after un/installing
- Add -devel subpackage to handle include files and examples
- Disable any static file in the package
* Fri Feb 16 2018 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.1-1
- New upstream release
- Support for OpenSSL 1.1 was added directly to the source code in upstream,
thus removing specific patch for it
- Docbook xsl stylesheet updated to a local path
* Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Fri Feb 02 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> - 1.0-4
- Switch to %%ldconfig_scriptlets
* Fri Dec 01 2017 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.0-3
- Add OpenSSL 1.1 API support for the package, avoiding the need of
compat-openssl10-devel package
* Mon Nov 20 2017 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.0-2
- Adjusted docbook xsl path to match the correct stylesheet
- Remove only *.la files, considering there aren't any *.a files
* Tue Sep 05 2017 Bruno E. O. Meneguele <brdeoliv@redhat.com> - 1.0-1
- New upstream release
- Add OpenSSL 1.0 compatibility package, due to issues with OpenSSL 1.1
- Remove libtool files
- Run ldconfig after un/installation to update *.so files
- Add -devel subpackage to handle include files and examples
* Wed Aug 02 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

134
ima-setup.sh Executable file
View file

@ -0,0 +1,134 @@
#!/bin/bash
#
# This script helps set up IMA.
#
IMA_SYSTEMD_POLICY=/etc/ima/ima-policy
IMA_POLICY_SYSFS=/sys/kernel/security/ima/policy
usage() {
echo "Set up IMA."
cat <<EOF
usage: $0 --policy=IMA_POLICY_PATH [--reinstall_threshold=NUM]
--policy
The path of IMA policy to be loaded. Sample polices are inside
/usr/share/ima/policies or you can use your own IMA policy
The path of IMA policy to be loaded. Sample polices are inside
/usr/share/ima/policies or you can use your own IMA policy
--reinstall_threshold
When there are >reinstall_threshold packages in the RPM DB missing IMA
signatures, reinstalling the packages to add IMA signatures to the
packages. By default, IMA sigatures will be obtained from the RPM DB.
However the RPM DB may not have the signatures. Dectect this case by
checking if there are >reinstall_threshold package missing IMA
signatures.
EOF
exit 1
}
for _opt in "$@"; do
case "$_opt" in
--policy=*)
ima_policy_path=${_opt#*=}
if [[ ! -e $ima_policy_path ]]; then
echo "$ima_policy_path doesn't exist"
exit 1
fi
;;
--reinstall_threshold=*)
reinstall_threshold=${_opt#*=}
;;
*)
usage
;;
esac
done
if [[ $# -eq 0 ]]; then
usage
fi
# Add IMA signatures
if test -f /run/ostree-booted; then
echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process."
else
echo "Adding IMA signatures to installed package files"
if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then
echo "Failed to add IMA signatures, abort"
exit 1
fi
fi
load_ima_keys() {
local _key_loaded
if line=$(keyctl describe %keyring:.ima); then
_ima_id=${line%%:*}
else
echo "Failed to get ID of the .ima keyring"
exit 1
fi
for i in /etc/keys/ima/*; do
if [ ! -f "${i}" ]; then
echo "No IMA key exist"
exit 1
fi
if ! evmctl import "${i}" "${_ima_id}" &>/dev/null; then
echo "Failed to load IMA key ${i}"
else
_key_loaded=yes
fi
done
if [[ $_key_loaded != yes ]]; then
echo "No IMA key loaded"
exit 1
fi
}
load_ima_policy() {
local ima_policy_path
ima_policy_path=$1
if ! test -f "$ima_policy_path"; then
echo "$ima_policy_path doesn't exist"
return 1
fi
if ! echo "$ima_policy_path" >"$IMA_POLICY_SYSFS"; then
echo "$ima_policy_path can't be loaded"
return 1
fi
# Let systemd load the IMA policy which will load LSM rules first so IMA
# policy containing rules like "appraise obj_type=ifconfig_exec_t" can be
# loaded
[[ -e /etc/ima ]] || mkdir -p /etc/ima/
if ! cp --preserve=xattr "$ima_policy_path" "$IMA_SYSTEMD_POLICY"; then
echo "Failed to copy $ima_policy_path to $IMA_SYSTEMD_POLICY"
return 1
fi
}
echo "Loading IMA keys"
load_ima_keys
# Include the dracut integrity module to load the IMA keys and policy
# automatically when there is a system reboot
if ! lsinitrd --mod | grep -q integrity; then
cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf
echo "Regenerating all initramfs images to include the dracut integrity module"
if ! dracut -f --regenerate-all; then
echo "Failed to Regenerate all initramfs images"
exit 1
fi
[[ $(uname -m) == s390x ]] && zipl &> /dev/null
fi
if ! load_ima_policy "$ima_policy_path"; then
echo "Failed to load IMA policy $ima_policy_path!"
exit 1
fi

View file

@ -1,12 +0,0 @@
diff -urNp ima-evm-utils-0.9/Makefile.am ima-evm-utils-0.9-patch/Makefile.am
--- ima-evm-utils-0.9/Makefile.am 2014-09-23 08:09:05.000000000 -0400
+++ ima-evm-utils-0.9-patch/Makefile.am 2014-10-31 13:00:03.492295123 -0400
@@ -24,7 +24,7 @@ rpm: $(tarname)
rpmbuild -ba --nodeps $(SPEC)
# requires asciidoc, xslproc, docbook-xsl
-MANPAGE_DOCBOOK_XSL = /usr/share/xml/docbook/stylesheet/docbook-xsl/manpages/docbook.xsl
+MANPAGE_DOCBOOK_XSL = http://docbook.sourceforge.net/release/xsl/current/xhtml-1_1/docbook.xsl
evmctl.1.html: README
@asciidoc -o $@ $<

View file

@ -0,0 +1,28 @@
# Skip some unsupported filesystems
# This list of the filesystems can be found on
# https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy
# PROC_SUPER_MAGIC
dont_appraise fsmagic=0x9fa0
# SYSFS_MAGIC
dont_appraise fsmagic=0x62656572
# DEBUGFS_MAGIC
dont_appraise fsmagic=0x64626720
# TMPFS_MAGIC
dont_appraise fsmagic=0x01021994
# RAMFS_MAGIC
dont_appraise fsmagic=0x858458f6
# DEVPTS_SUPER_MAGIC
dont_appraise fsmagic=0x1cd1
# BINFMTFS_MAGIC
dont_appraise fsmagic=0x42494e4d
# SECURITYFS_MAGIC
dont_appraise fsmagic=0x73636673
# SELINUX_MAGIC
dont_appraise fsmagic=0xf97cff8c
# CGROUP_SUPER_MAGIC
dont_appraise fsmagic=0x27e0eb
# NSFS_MAGIC
dont_appraise fsmagic=0x6e736673
appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig
appraise func=BPRM_CHECK appraise_type=imasig

View file

@ -0,0 +1,37 @@
# PROC_SUPER_MAGIC
dont_measure fsmagic=0x9fa0
# SYSFS_MAGIC
dont_measure fsmagic=0x62656572
# DEBUGFS_MAGIC
dont_measure fsmagic=0x64626720
# TMPFS_MAGIC
dont_measure fsmagic=0x01021994
# DEVPTS_SUPER_MAGIC
dont_measure fsmagic=0x1cd1
# BINFMTFS_MAGIC
dont_measure fsmagic=0x42494e4d
# SECURITYFS_MAGIC
dont_measure fsmagic=0x73636673
# SELINUX_MAGIC
dont_measure fsmagic=0xf97cff8c
# SMACK_MAGIC
dont_measure fsmagic=0x43415d53
# CGROUP_SUPER_MAGIC
dont_measure fsmagic=0x27e0eb
# CGROUP2_SUPER_MAGIC
dont_measure fsmagic=0x63677270
# NSFS_MAGIC
dont_measure fsmagic=0x6e736673
# EFIVARFS_MAGIC
dont_measure fsmagic=0xde5e81e4
# OVERLAYFS_MAGIC
# when containers are used we almost always want to ignore them
dont_measure fsmagic=0x794c7630
# Measure and log keys loaded onto the .ima keyring
measure func=KEY_CHECK keyrings=.ima
# Measure and log executables
measure func=BPRM_CHECK
# Measure and log shared libraries
measure func=FILE_MMAP mask=MAY_EXEC

2
policy_list Normal file
View file

@ -0,0 +1,2 @@
01-appraise-executable-and-lib-signatures
02-keylime-remote-attestation

View file

@ -1 +1 @@
b4005df0bcf63ec33744c6dea5e670b2 ima-evm-utils-0.9.tar.gz
SHA512 (ima-evm-utils-1.6.2.tar.gz) = dfd82ba7c48c14fd31d687214a2b0cfcf269bdea42d4a0ebc872a72205f880c509ed5c5cd55dec7e94444e6f3bdc3c071ec6c2e3eba1e6579edb8ef11aa158a1