// SPDX-License-Identifier: GPL-2.0-or-later /* System trusted keyring for trusted public keys * *Copyright(C)2012RedHat,Inc.AllRightsReserved. *WrittenbyDavidHowells(dhowells@redhat.com)
*/
#ifdef CONFIG_SECONDARY_TRUSTED_KEYRING /** *restrict_link_by_builtin_and_secondary_trusted-Restrictkeyring *additionbybothbuilt-inandsecondarykeyrings. *@dest_keyring:Keyringbeinglinkedto. *@type:Thetypeofkeybeingadded. *@payload:Thepayloadofthenewkey. *@restrict_key:Aringofkeysthatcanbeusedtovouchforthenewcert. * *Restricttheadditionofkeysintoakeyringbasedonthekey-to-be-added *beingvouchedforbyakeyineitherthebuilt-inorthesecondarysystem *keyrings.
*/ int restrict_link_by_builtin_and_secondary_trusted( struct key *dest_keyring, conststruct key_type *type, constunion key_payload *payload, struct key *restrict_key)
{ /* If we have a secondary trusted keyring, then that contains a link *throughtothebuiltinkeyringandthesearchwillfollowthatlink.
*/ if (type == &key_type_keyring &&
dest_keyring == secondary_trusted_keys &&
payload == &builtin_trusted_keys->payload) /* Allow the builtin keyring to be added to the secondary */ return0;
/** *restrict_link_by_digsig_builtin_and_secondary-RestrictbydigitalSignature. *@dest_keyring:Keyringbeinglinkedto. *@type:Thetypeofkeybeingadded. *@payload:Thepayloadofthenewkey. *@restrict_key:Aringofkeysthatcanbeusedtovouchforthenewcert. * *Restricttheadditionofkeysintoakeyringbasedonthekey-to-be-added *beingvouchedforbyakeyineitherthebuilt-inorthesecondarysystem *keyrings.ThenewkeymusthavethedigitalSignatureusagefieldset.
*/ int restrict_link_by_digsig_builtin_and_secondary(struct key *dest_keyring, conststruct key_type *type, constunion key_payload *payload, struct key *restrict_key)
{ /* If we have a secondary trusted keyring, then that contains a link *throughtothebuiltinkeyringandthesearchwillfollowthatlink.
*/ if (type == &key_type_keyring &&
dest_keyring == secondary_trusted_keys &&
payload == &builtin_trusted_keys->payload) /* Allow the builtin keyring to be added to the secondary */ return0;
/* The data should be detached - so we need to supply it. */ if (data && pkcs7_supply_detached_data(pkcs7, data, len) < 0) {
pr_err("PKCS#7 signature with non-detached data\n");
ret = -EBADMSG; goto error;
}
ret = pkcs7_verify(pkcs7, usage); if (ret < 0) goto error;
ret = is_key_on_revocation_list(pkcs7); if (ret != -ENOKEY) {
pr_devel("PKCS#7 key is on revocation list\n"); goto error;
}
if (!trusted_keys) {
trusted_keys = builtin_trusted_keys;
} elseif (trusted_keys == VERIFY_USE_SECONDARY_KEYRING) { #ifdef CONFIG_SECONDARY_TRUSTED_KEYRING
trusted_keys = secondary_trusted_keys; #else
trusted_keys = builtin_trusted_keys; #endif
} elseif (trusted_keys == VERIFY_USE_PLATFORM_KEYRING) { #ifdef CONFIG_INTEGRITY_PLATFORM_KEYRING
trusted_keys = platform_trusted_keys; #else
trusted_keys = NULL; #endif if (!trusted_keys) {
ret = -ENOKEY;
pr_devel("PKCS#7 platform keyring is not available\n"); goto error;
}
}
ret = pkcs7_validate_trust(pkcs7, trusted_keys); if (ret < 0) { if (ret == -ENOKEY)
pr_devel("PKCS#7 signature not signed with a trusted key\n"); goto error;
}
if (view_content) {
size_t asn1hdrlen;
ret = pkcs7_get_content_data(pkcs7, &data, &len, &asn1hdrlen); if (ret < 0) { if (ret == -ENODATA)
pr_devel("PKCS#7 message does not contain data\n"); goto error;
}
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.13Bemerkung:
(vorverarbeitet am 2026-09-28)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.