Switch Secure Boot to lock down in integrity mode (rhbz 1815571)
This commit is contained in:
parent
5902b3e0f2
commit
abd266769c
3 changed files with 6 additions and 3 deletions
|
|
@ -303,7 +303,7 @@ index 77ea96b794bd..a119e1bc9623 100644
|
|||
+
|
||||
+#ifdef CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT
|
||||
+ if (efi_enabled(EFI_SECURE_BOOT))
|
||||
+ security_lock_kernel_down("EFI Secure Boot mode", LOCKDOWN_CONFIDENTIALITY_MAX);
|
||||
+ security_lock_kernel_down("EFI Secure Boot mode", LOCKDOWN_INTEGRITY_MAX);
|
||||
+#endif
|
||||
+
|
||||
dmi_setup();
|
||||
|
|
|
|||
|
|
@ -1815,6 +1815,9 @@ fi
|
|||
#
|
||||
#
|
||||
%changelog
|
||||
* Fri Mar 20 2020 Jeremy Cline <jcline@redhat.com>
|
||||
- Switch Secure Boot to lock down to integrity mode (rhbz 1815571)
|
||||
|
||||
* Fri Mar 20 2020 Justin M. Forbes <jforbes@fedoraproject.org>
|
||||
- Fix CVE-2019-19769 (rhbz 1786174 1786175)
|
||||
|
||||
|
|
|
|||
|
|
@ -3,7 +3,7 @@ From: Jeremy Cline <jcline@redhat.com>
|
|||
Date: Wed, 30 Oct 2019 14:37:49 +0000
|
||||
Subject: [PATCH] s390: Lock down the kernel when the IPL secure flag is set
|
||||
|
||||
Automatically lock down the kernel to LOCKDOWN_CONFIDENTIALITY_MAX if
|
||||
Automatically lock down the kernel to LOCKDOWN_INTEGRITY_MAX if
|
||||
the IPL secure flag is set.
|
||||
|
||||
Suggested-by: Philipp Rudo <prudo@redhat.com>
|
||||
|
|
@ -56,7 +56,7 @@ index 9cbf490fd162..0510ecdfc3f6 100644
|
|||
log_component_list();
|
||||
|
||||
+ if (ipl_get_secureboot())
|
||||
+ security_lock_kernel_down("Secure IPL mode", LOCKDOWN_CONFIDENTIALITY_MAX);
|
||||
+ security_lock_kernel_down("Secure IPL mode", LOCKDOWN_INTEGRITY_MAX);
|
||||
+
|
||||
/* Have one command line that is parsed and saved in /proc/cmdline */
|
||||
/* boot_command_line has been already set up in early.c */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue