mbox series

[v3,ima-evm-utils,0/2] make default hash algorithm dynamic

Message ID 20210820224917.101053-1-bmeneg@redhat.com (mailing list archive)
Headers show
Series make default hash algorithm dynamic | expand

Message

Bruno Meneguele Aug. 20, 2021, 10:49 p.m. UTC
In order to allow the distros and users to set their own security policies,
this patch enable a option in configuration time to set the default hash
algorithm to be used. Today, only SHA1 and SHA256 is supported by
ima-evm-utils, but it'll change some day, enabling this dynamic mechanism
facilitates distro maintainers' lives.

At the same time, move from SHA1 to SHA256 default hash algorithm, following
the general movement of dropping SHA1 support in the major distros due to
its weaknesses.

Changelog:
v2: add a config time option for setting DEFAULT_HASH_ALGO.

Bruno Meneguele (2):
  set default hash algorithm in configuration time
  make SHA-256 the default hash algorithm

 README                  |  2 +-
 configure.ac            |  1 +
 m4/default-hash-algo.m4 | 48 +++++++++++++++++++++++++++++++++++++++++
 src/evmctl.c            |  4 ++--
 src/imaevm.h            |  4 ++++
 src/libimaevm.c         |  2 +-
 6 files changed, 57 insertions(+), 4 deletions(-)
 create mode 100644 m4/default-hash-algo.m4