summaryrefslogtreecommitdiff
path: root/certs
AgeCommit message (Expand)AuthorFilesLines
2022-09-24certs: make system keyring depend on built-in x509 parserMasahiro Yamada1-1/+1
2022-08-10Merge tag 'kbuild-v5.20' of git://git.kernel.org/pub/scm/linux/kernel/git/mas...Linus Torvalds4-15/+43
2022-07-27certs: unify blacklist_hashes.c and blacklist_nohashes.cMasahiro Yamada3-14/+5
2022-07-27certs: move scripts/check-blacklist-hashes.awk to certs/Masahiro Yamada2-1/+38
2022-07-24certs: make system keyring depend on x509 parserAdam Borowski1-0/+1
2022-06-21Merge tag 'certs-20220621' of git://git.kernel.org/pub/scm/linux/kernel/git/d...Linus Torvalds5-75/+9
2022-06-21certs: Move load_certificate_list() to be with the asymmetric keys codeDavid Howells5-75/+9
2022-06-15certs: fix and refactor CONFIG_SYSTEM_BLACKLIST_HASH_LIST buildMasahiro Yamada3-12/+12
2022-06-15certs/blacklist_hashes.c: fix const confusion in certs blacklistMasahiro Yamada1-1/+1
2022-06-10certs: Convert spaces in certs/Makefile to a tabDavid Howells1-1/+1
2022-06-08cert host tools: Stop complaining about deprecated OpenSSL functionsLinus Torvalds1-0/+7
2022-05-26Merge tag 'kbuild-v5.19' of git://git.kernel.org/pub/scm/linux/kernel/git/mas...Linus Torvalds1-2/+2
2022-05-23certs: Explain the rationale to call panic()Mickaël Salaün1-0/+9
2022-05-23certs: Allow root user to append signed hashes to the blacklist keyringMickaël Salaün2-21/+85
2022-05-23certs: Check that builtin blacklist hashes are validMickaël Salaün3-3/+19
2022-05-23certs: Make blacklist_vet_description() more strictMickaël Salaün1-10/+36
2022-05-23certs: Factor out the blacklist hash creationMickaël Salaün1-18/+58
2022-04-05kbuild: Allow kernel installation packaging to override pkg-configChun-Tse Shao1-2/+2
2022-03-31Merge tag 'kbuild-v5.18-v2' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds2-29/+11
2022-03-08KEYS: Introduce link restriction for machine keysEric Snowberg1-1/+34
2022-03-08KEYS: store reference to machine keyringEric Snowberg1-0/+9
2022-03-03certs: simplify empty certs creation in certs/MakefileMasahiro Yamada1-10/+11
2022-03-03certs: include certs/signing_key.x509 unconditionallyMasahiro Yamada2-19/+0
2022-01-23certs: Fix build error when CONFIG_MODULE_SIG_KEY is emptyMasahiro Yamada1-1/+1
2022-01-23certs: Fix build error when CONFIG_MODULE_SIG_KEY is PKCS#11 URIMasahiro Yamada1-1/+1
2022-01-08certs: move scripts/extract-cert to certs/Masahiro Yamada3-4/+172
2022-01-08kbuild: do not quote string values in include/config/auto.confMasahiro Yamada1-8/+2
2022-01-08certs: simplify $(srctree)/ handling and remove config_filename macroMasahiro Yamada1-19/+13
2022-01-08certs: remove misleading comments about GCC PRMasahiro Yamada1-2/+0
2022-01-08certs: refactor file cleaningMasahiro Yamada1-4/+5
2022-01-08certs: remove unneeded -I$(srctree) option for system_certificates.oMasahiro Yamada1-3/+0
2022-01-08certs: unify duplicated cmd_extract_certs and improve the logMasahiro Yamada1-6/+3
2022-01-08certs: use $< and $@ to simplify the key generation ruleMasahiro Yamada1-3/+2
2021-12-11certs: use if_changed to re-generate the key when the key type is changedMasahiro Yamada1-24/+6
2021-12-11certs: use 'cmd' to hide openssl output in silent builds more simplyMasahiro Yamada1-6/+6
2021-12-11certs: remove noisy messages while generating the signing keyMasahiro Yamada1-11/+0
2021-12-11certs: check-in the default x509 config fileMasahiro Yamada2-18/+23
2021-12-11certs: remove meaningless $(error ...) in certs/MakefileMasahiro Yamada1-3/+0
2021-12-11certs: move the 'depends on' to the choice of module signing keysMasahiro Yamada1-3/+1
2021-08-23certs: Add support for using elliptic curve keys for signing modulesStefan Berger2-0/+39
2021-08-23certs: Trigger creation of RSA module signing key if it's not an RSA keyStefan Berger1-0/+8
2021-05-08Merge tag 'kbuild-v5.13-2' of git://git.kernel.org/pub/scm/linux/kernel/git/m...Linus Torvalds1-2/+2
2021-05-01Merge tag 'integrity-v5.13' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds4-4/+47
2021-05-02.gitignore: prefix local generated files with a slashMasahiro Yamada1-2/+2
2021-04-26ima: ensure IMA_APPRAISE_MODSIG has necessary dependenciesNayna Jain3-2/+5
2021-04-26certs: add 'x509_revocation_list' to gitignoreLinus Torvalds1-0/+1
2021-04-09ima: enable loading of build time generated key on .ima keyringNayna Jain2-11/+52
2021-04-09ima: enable signing of modules with build time generated keyNayna Jain2-1/+9
2021-03-11certs: Add ability to preload revocation certsEric Snowberg4-2/+67
2021-03-11certs: Move load_system_certificate_list to a common functionEric Snowberg4-47/+70