Re: [PATCH v9 7/8] IMA: define a builtin critical data measurement policy

From: Tushar Sugandhi
Date: Tue Jan 05 2021 - 15:31:27 EST




On 2020-12-24 6:41 a.m., Mimi Zohar wrote:
On Sat, 2020-12-12 at 10:02 -0800, Tushar Sugandhi wrote:
From: Lakshmi Ramasubramanian <nramas@xxxxxxxxxxxxxxxxxxx>

Define a new critical data builtin policy to allow measuring
early kernel integrity critical data before a custom IMA policy
is loaded.

Add critical data to built-in IMA rules if the kernel command line
contains "ima_policy=critical_data".

This sentence isn't really necessary.

Will remove.

Update the documentation on kernel parameters to document
the new critical data builtin policy.

Signed-off-by: Lakshmi Ramasubramanian <nramas@xxxxxxxxxxxxxxxxxxx>
Reviewed-by: Tyler Hicks <tyhicks@xxxxxxxxxxxxxxxxxxx>

Otherwise,
Reviewed-by: Mimi Zohar <zohar@xxxxxxxxxxxxx>
Thanks again for the "Reviewed-by" tag.

Thanks,
Tushar

thanks,

Mimi