[prev in list] [next in list] [prev in thread] [next in thread]
List: linux-security-module
Subject: [PATCH v2 18/23] ima: add audit log support for larger hashes
From: Mimi Zohar <zohar () linux ! vnet ! ibm ! com>
Date: 2013-10-21 22:43:03
Message-ID: 1382395388-8108-19-git-send-email-zohar () linux ! vnet ! ibm ! com
[Download RAW message or body]
Different files might be signed based on different hash algorithms.
This patch prefixes the audit log measurement hash with the hash
algorithm.
Changelog:
- use generic HASH_ALGO defintions
- use ':' as delimiter between the hash algorithm and the digest
(Roberto Sassu)
Signed-off-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: Roberto Sassu <roberto.sassu@polito.it>
---
security/integrity/ima/ima_api.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/security/integrity/ima/ima_api.c b/security/integrity/ima/ima_api.c
index baa3481..f22725e 100644
--- a/security/integrity/ima/ima_api.c
+++ b/security/integrity/ima/ima_api.c
@@ -287,6 +287,12 @@ void ima_audit_measurement(struct integrity_iint_cache *iint,
audit_log_format(ab, "file=");
audit_log_untrustedstring(ab, filename);
audit_log_format(ab, " hash=");
+ if (iint->ima_hash->algo != HASH_ALGO_SHA1 &&
+ iint->ima_hash->algo != HASH_ALGO_MD5) {
+ audit_log_untrustedstring(ab,
+ hash_algo_name[iint->ima_hash->algo]);
+ audit_log_format(ab, ":");
+ }
audit_log_untrustedstring(ab, hash);
audit_log_task_info(ab, current);
--
1.8.1.4
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic