Skip to content
Snippets Groups Projects
user avatar
Luca Boccassi authored
If enabled, we fallback to the platform keyring if the trusted keyring
doesn't have the key used to sign the ipe policy. But if pkcs7_verify()
rejects the key for other reasons, such as usage restrictions, we do not
fallback. Do so, following the same change in dm-verity.

Signed-off-by: default avatarLuca Boccassi <bluca@debian.org>
Suggested-by: default avatarSerge Hallyn <serge@hallyn.com>
[FW: fixed some line length issues and a typo in the commit message]
Signed-off-by: default avatarFan Wu <wufan@kernel.org>
f40998a8
Name Last commit Last update
..