Show patches with: State = Action Required       |   9158 patches
« 1 2 ... 33 34 3591 92 »
Patch Series A/R/T S/W/F Date Submitter Delegate State
[4/4] ima: support fs-verity file digest based signatures ima: support fs-verity signatures stored as - - - --- 2021-11-29 Mimi Zohar New
[3/4] ima: limit including fs-verity's file digest in measurement list ima: support fs-verity signatures stored as - - - --- 2021-11-29 Mimi Zohar New
[2/4] ima: define a new signature type named IMA_VERITY_DIGSIG ima: support fs-verity signatures stored as - - - --- 2021-11-29 Mimi Zohar New
[1/4] fs-verity: define a function to return the integrity protected file digest ima: support fs-verity signatures stored as - - - --- 2021-11-29 Mimi Zohar New
fix iint inode add race resulting in duplication of iint entries fix iint inode add race resulting in duplication of iint entries - - - --- 2021-11-29 James Bottomley New
[v4,2/2] selftests: tpm2: Reset the dictionary attack lock selftests: tpm2: Determine available PCR bank - - - --- 2021-11-28 Stefan Berger New
[v4,1/2] selftests: tpm2: Determine available PCR bank selftests: tpm2: Determine available PCR bank 1 - 1 --- 2021-11-28 Stefan Berger New
tpm: make const pointer desc a static const array tpm: make const pointer desc a static const array - - - --- 2021-11-27 Colin Ian King New
[RFC,3/3] ima: make the integrity inode cache per namespace Namespace IMA - - - --- 2021-11-27 James Bottomley New
[RFC,2/3] ima: Namespace IMA Namespace IMA 1 - - --- 2021-11-27 James Bottomley New
[RFC,1/3] userns: add uuid field Namespace IMA - - - --- 2021-11-27 James Bottomley New
[v2,6/6] module: Move duplicate mod_check_sig users code to mod_parse_sig KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v2,5/6] module: Use key_being_used_for for log messages in verify_appended_signature KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v2,4/6] module: strip the signature marker in the verification function. KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v2,3/6] kexec_file: Don't opencode appended signature verification. KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v2,2/6] powerpc/kexec_file: Add KEXEC_SIG support. KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v2,1/6] s390/kexec_file: Don't opencode appended signature check. KEXEC_SIG with appended signature - - - --- 2021-11-25 Michal Suchánek New
[v3,3/3] selftests: tpm2: Add support for SHA-384 and SHA-512 selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-25 Stefan Berger New
[v3,2/3] selftests: tpm2: Reset the dictionary attack lock selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-25 Stefan Berger New
[v3,1/3] selftests: tpm2: Probe for available PCR bank selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-25 Stefan Berger New
ima: Fix trivial typos in the comments ima: Fix trivial typos in the comments - 1 - --- 2021-11-24 Austin Kim New
[v5,2/2] integrity: support including firmware ".platform" keys at build time integrity: support including firmware ".platform" keys at build time - 1 - --- 2021-11-24 Nayna Jain New
[v5,1/2] certs: export load_certificate_list() to be used outside certs/ integrity: support including firmware ".platform" keys at build time - 1 - --- 2021-11-24 Nayna Jain New
security:trusted_tpm2: Fix memory leak in tpm2_key_encode() security:trusted_tpm2: Fix memory leak in tpm2_key_encode() - - - --- 2021-11-24 Jianglei Nie New
[v2,3/3] selftests: tpm2: Add support for SHA-384 and SHA-512 selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-24 Stefan Berger New
[v2,2/3] selftests: tpm2: Reset the dictionary attack lock selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-24 Stefan Berger New
[v2,1/3] selftests: tpm2: Probe for available PCR bank selftests: tpm2: Probe for available PCR bank - - - --- 2021-11-24 Stefan Berger New
[3/3] Add tests to verify kexec of blacklist and non blacklist kernel [1/3] selftest/kexec: fix "ignored null byte in input" warning - - - --- 2021-11-24 R Nageswara Sastry New
[2/3] selftests/kexec: Enable secureboot tests for PowerPC [1/3] selftest/kexec: fix "ignored null byte in input" warning - 1 1 --- 2021-11-24 R Nageswara Sastry New
[1/3] selftest/kexec: fix "ignored null byte in input" warning [1/3] selftest/kexec: fix "ignored null byte in input" warning - - - --- 2021-11-24 R Nageswara Sastry New
[v8,17/17] integrity: Only use machine keyring when uefi_check_trust_mok_keys is true Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,16/17] integrity: Trust MOK keys if MokListTrustedRT found Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,15/17] efi/mokvar: move up init order Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,14/17] KEYS: link machine trusted keys to secondary_trusted_keys Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,13/17] integrity: store reference to machine keyring Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,12/17] KEYS: integrity: change link restriction to trust the machine keyring Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,11/17] KEYS: Introduce link restriction for machine keys Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,10/17] KEYS: add a reference to machine keyring Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,09/17] KEYS: Rename get_builtin_and_secondary_restriction Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,08/17] integrity: add new keyring handler for mok keys Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,07/17] integrity: restrict INTEGRITY_KEYRING_MACHINE to restrict_link_by_ca Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,06/17] KEYS: CA link restriction Enroll kernel keys thru MOK - - - --- 2021-11-24 Eric Snowberg New
[v8,05/17] X.509: Parse Basic Constraints for CA Enroll kernel keys thru MOK - - - --- 2021-11-24 Eric Snowberg New
[v8,04/17] integrity: Do not allow machine keyring updates following init Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,03/17] integrity: Introduce a Linux keyring called machine Enroll kernel keys thru MOK - 2 - --- 2021-11-24 Eric Snowberg New
[v8,02/17] integrity: Fix warning about missing prototypes Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v8,01/17] KEYS: Create static version of public_key_verify_signature Enroll kernel keys thru MOK - 1 - --- 2021-11-24 Eric Snowberg New
[v30,15/28] LSM: Ensure the correct LSM context releaser Untitled series #584927 3 2 - --- 2021-11-24 Casey Schaufler New
[v30,13/28] LSM: Use lsmblob in security_cred_getsecid Untitled series #584927 2 2 - --- 2021-11-24 Casey Schaufler New
[v30,12/28] LSM: Use lsmblob in security_inode_getsecid Untitled series #584927 2 2 - --- 2021-11-24 Casey Schaufler New
[v30,11/28] LSM: Use lsmblob in security_task_getsecid Untitled series #584927 2 2 - --- 2021-11-24 Casey Schaufler New
[2/2] selftests: tpm2: Reset the dictionary attack lock selftests: tpm2: Probe for available PCR bank - - 1 --- 2021-11-22 Stefan Berger New
[1/2] selftests: tpm: Probe for available PCR bank selftests: tpm2: Probe for available PCR bank - - 1 --- 2021-11-22 Stefan Berger New
[v7,17/17] integrity: Only use machine keyring when uefi_check_trust_mok_keys is true Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,16/17] integrity: Trust MOK keys if MokListTrustedRT found Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,15/17] efi/mokvar: move up init order Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,14/17] integrity: store reference to machine keyring Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,13/17] KEYS: link secondary_trusted_keys to machine trusted keys Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,12/17] KEYS: integrity: change link restriction to trust the machine keyring Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,11/17] KEYS: Introduce link restriction for machine keys Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,10/17] KEYS: add a reference to machine keyring Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,09/17] KEYS: Rename get_builtin_and_secondary_restriction Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,08/17] integrity: add new keyring handler for mok keys Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,07/17] integrity: Fix warning about missing prototypes Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,06/17] integrity: restrict INTEGRITY_KEYRING_MACHINE to restrict_link_by_ca Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,05/17] KEYS: CA link restriction Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,04/17] X.509: Parse Basic Constraints for CA Enroll kernel keys thru MOK - - - --- 2021-11-16 Eric Snowberg New
[v7,03/17] KEYS: Create static version of public_key_verify_signature Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,02/17] integrity: Do not allow machine keyring updates following init Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v7,01/17] integrity: Introduce a Linux keyring called machine Enroll kernel keys thru MOK - 1 - --- 2021-11-16 Eric Snowberg New
[v17,3/3] selftest/interpreter: Add tests for trusted_for(2) policies Add trusted_for(2) (was O_MAYEXEC) - 2 - --- 2021-11-15 Mickaël Salaün New
[v17,2/3] arch: Wire up trusted_for(2) Add trusted_for(2) (was O_MAYEXEC) 1 2 - --- 2021-11-15 Mickaël Salaün New
[v17,1/3] fs: Add trusted_for(2) syscall implementation and related sysctl Add trusted_for(2) (was O_MAYEXEC) 1 - - --- 2021-11-15 Mickaël Salaün New
char: tpm: cr50_i2c: Drop if with an always false condition char: tpm: cr50_i2c: Drop if with an always false condition - - - --- 2021-11-12 Uwe Kleine-König New
[RFC,5/5] shmem: Add fsverity support shmem/fsverity: Prepare for mandatory integrity enforcement - - - --- 2021-11-12 Roberto Sassu New
[RFC,4/5] shmem: Avoid segfault in shmem_read_mapping_page_gfp() shmem/fsverity: Prepare for mandatory integrity enforcement - - - --- 2021-11-12 Roberto Sassu New
[RFC,3/5] fsverity: Do initialization earlier shmem/fsverity: Prepare for mandatory integrity enforcement - - - --- 2021-11-12 Roberto Sassu New
[RFC,2/5] fsverity: Revalidate built-in signatures at file open shmem/fsverity: Prepare for mandatory integrity enforcement - - - --- 2021-11-12 Roberto Sassu New
[RFC,1/5] fsverity: Introduce fsverity_get_file_digest() shmem/fsverity: Prepare for mandatory integrity enforcement - - - --- 2021-11-12 Roberto Sassu New
[v4,2/2] integrity: support including firmware ".platform" keys at build time integrity: support including firmware ".platform" keys at build time - - - --- 2021-11-11 Nayna Jain New
[v4,1/2] certs: export load_certificate_list() to be used outside certs/ integrity: support including firmware ".platform" keys at build time - - - --- 2021-11-11 Nayna Jain New
[v16,3/3] selftest/interpreter: Add tests for trusted_for(2) policies Add trusted_for(2) (was O_MAYEXEC) - 2 - --- 2021-11-10 Mickaël Salaün New
[v16,2/3] arch: Wire up trusted_for(2) Add trusted_for(2) (was O_MAYEXEC) 1 2 - --- 2021-11-10 Mickaël Salaün New
[v16,1/3] fs: Add trusted_for(2) syscall implementation and related sysctl Add trusted_for(2) (was O_MAYEXEC) 1 - - --- 2021-11-10 Mickaël Salaün New
[RFC] ima: differentiate overlay, pivot_root, and other pathnames [RFC] ima: differentiate overlay, pivot_root, and other pathnames - - - --- 2021-11-08 Mimi Zohar New
tpm_tis: Fix an error handling path in 'tpm_tis_core_init()' tpm_tis: Fix an error handling path in 'tpm_tis_core_init()' - 1 - --- 2021-11-06 Christophe JAILLET New
[2/2] module: Move duplicate mod_check_sig users code to mod_parse_sig [1/2] module: Use key_being_used_for for log messages in verify_appended_signature - - - --- 2021-11-05 Michal Suchánek New
[1/2] module: Use key_being_used_for for log messages in verify_appended_signature [1/2] module: Use key_being_used_for for log messages in verify_appended_signature - - - --- 2021-11-05 Michal Suchánek New
[RFC] integrity: disassociate ima_filter_rule from security_audit_rule [RFC] integrity: disassociate ima_filter_rule from security_audit_rule - - - --- 2021-11-04 Casey Schaufler New
[v19,5/5] tpm: Add YAML schema for TPM TIS I2C options Add tpm i2c ptp driver - 1 - --- 2021-11-04 Amir Mizinski New
[v19,4/5] tpm: tpm_tis: Add tpm_tis_i2c driver Add tpm i2c ptp driver - - 2 --- 2021-11-04 Amir Mizinski New
[v19,3/5] tpm: tpm_tis: Verify TPM_STS register is valid after locality request Add tpm i2c ptp driver - - - --- 2021-11-04 Amir Mizinski New
[v19,2/5] tpm: tpm_tis: Rewrite "tpm_tis_req_canceled()" Add tpm i2c ptp driver - - - --- 2021-11-04 Amir Mizinski New
[v19,1/5] tpm_tis: Fix expected bit handling Add tpm i2c ptp driver - 1 - --- 2021-11-04 Amir Mizinski New
[ima-evm-utils] travis: use alt:sisyphus from docker.io [ima-evm-utils] travis: use alt:sisyphus from docker.io - - - --- 2021-11-02 Mimi Zohar New
[v18,6/6] tpm: Add YAML schema for TPM TIS I2C options Add tpm i2c ptp driver - 1 - --- 2021-11-02 Amir Mizinski New
[v18,5/6] tpm: tpm_tis: Add tpm_tis_i2c driver Add tpm i2c ptp driver - - 2 --- 2021-11-02 Amir Mizinski New
[v18,4/6] tpm: tpm_tis: Verify TPM_STS register is valid after locality request Add tpm i2c ptp driver - - - --- 2021-11-02 Amir Mizinski New
[v18,3/6] tpm: Handle an exception for TPM Firmware Update mode. Add tpm i2c ptp driver - - - --- 2021-11-02 Amir Mizinski New
[v18,2/6] tpm: tpm_tis: Rewrite "tpm_tis_req_canceled()" Add tpm i2c ptp driver - - - --- 2021-11-02 Amir Mizinski New
« 1 2 ... 33 34 3591 92 »