summaryrefslogtreecommitdiff
path: root/security/integrity
diff options
context:
space:
mode:
authorMichal Suchanek <msuchanek@suse.de>2023-09-07 19:52:19 +0300
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2023-11-28 20:20:01 +0300
commit3293de84bf3e041242b9826bb2a439a1f4d3da7d (patch)
treed370ecb8222a15df1cf1ed773b9cb893facfb5b0 /security/integrity
parentc21a0913da18574d71553622d70ec52ac6fb99a9 (diff)
downloadlinux-3293de84bf3e041242b9826bb2a439a1f4d3da7d.tar.xz
integrity: powerpc: Do not select CA_MACHINE_KEYRING
commit 3edc22655647378dea01900f7b04e017ff96bda9 upstream. No other platform needs CA_MACHINE_KEYRING, either. This is policy that should be decided by the administrator, not Kconfig dependencies. Cc: stable@vger.kernel.org # v6.6+ Fixes: d7d91c4743c4 ("integrity: PowerVM machine keyring enablement") Signed-off-by: Michal Suchanek <msuchanek@suse.de> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'security/integrity')
-rw-r--r--security/integrity/Kconfig2
1 files changed, 0 insertions, 2 deletions
diff --git a/security/integrity/Kconfig b/security/integrity/Kconfig
index 232191ee09e3..b6e074ac0227 100644
--- a/security/integrity/Kconfig
+++ b/security/integrity/Kconfig
@@ -68,8 +68,6 @@ config INTEGRITY_MACHINE_KEYRING
depends on INTEGRITY_ASYMMETRIC_KEYS
depends on SYSTEM_BLACKLIST_KEYRING
depends on LOAD_UEFI_KEYS || LOAD_PPC_KEYS
- select INTEGRITY_CA_MACHINE_KEYRING if LOAD_PPC_KEYS
- select INTEGRITY_CA_MACHINE_KEYRING_MAX if LOAD_PPC_KEYS
help
If set, provide a keyring to which Machine Owner Keys (MOK) may
be added. This keyring shall contain just MOK keys. Unlike keys