 7ef84e65ec
			
		
	
	
	7ef84e65ec
	
	
	
		
			
			The integrity subsystem has lots of options and takes more than half of the security menu. This patch consolidates the options under "integrity", which are hidden if not enabled. This change does not affect existing configurations. Re-configuration is not needed. Changes v4: - no need to change "integrity subsystem" to menuconfig as options are hidden, when not enabled. (Mimi) - add INTEGRITY Kconfig help description Changes v3: - dependency to INTEGRITY removed when behind 'if INTEGRITY' Changes v2: - previous patch moved integrity out of the 'security' menu. This version keeps integrity as a security option (Mimi). Signed-off-by: Dmitry Kasatkin <d.kasatkin@samsung.com> Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
		
			
				
	
	
		
			44 lines
		
	
	
	
		
			1.3 KiB
			
		
	
	
	
		
			Text
		
	
	
	
	
	
			
		
		
	
	
			44 lines
		
	
	
	
		
			1.3 KiB
			
		
	
	
	
		
			Text
		
	
	
	
	
	
| config EVM
 | |
| 	boolean "EVM support"
 | |
| 	select KEYS
 | |
| 	select ENCRYPTED_KEYS
 | |
| 	select CRYPTO_HMAC
 | |
| 	select CRYPTO_SHA1
 | |
| 	default n
 | |
| 	help
 | |
| 	  EVM protects a file's security extended attributes against
 | |
| 	  integrity attacks.
 | |
| 
 | |
| 	  If you are unsure how to answer this question, answer N.
 | |
| 
 | |
| config EVM_ATTR_FSUUID
 | |
| 	bool "FSUUID (version 2)"
 | |
| 	default y
 | |
| 	depends on EVM
 | |
| 	help
 | |
| 	  Include filesystem UUID for HMAC calculation.
 | |
| 
 | |
| 	  Default value is 'selected', which is former version 2.
 | |
| 	  if 'not selected', it is former version 1
 | |
| 
 | |
| 	  WARNING: changing the HMAC calculation method or adding
 | |
| 	  additional info to the calculation, requires existing EVM
 | |
| 	  labeled file systems to be relabeled.
 | |
| 
 | |
| config EVM_EXTRA_SMACK_XATTRS
 | |
| 	bool "Additional SMACK xattrs"
 | |
| 	depends on EVM && SECURITY_SMACK
 | |
| 	default n
 | |
| 	help
 | |
| 	  Include additional SMACK xattrs for HMAC calculation.
 | |
| 
 | |
| 	  In addition to the original security xattrs (eg. security.selinux,
 | |
| 	  security.SMACK64, security.capability, and security.ima) included
 | |
| 	  in the HMAC calculation, enabling this option includes newly defined
 | |
| 	  Smack xattrs: security.SMACK64EXEC, security.SMACK64TRANSMUTE and
 | |
| 	  security.SMACK64MMAP.
 | |
| 
 | |
| 	  WARNING: changing the HMAC calculation method or adding
 | |
| 	  additional info to the calculation, requires existing EVM
 | |
| 	  labeled file systems to be relabeled.
 | |
| 
 |