Skip to content

Commit d892ed0

Browse files
committed
powerpc/configs/64s: Add secure boot options to defconfig
Add the numerous options required to get secure boot enabled. Signed-off-by: Michael Ellerman <mpe@ellerman.id.au> Link: https://msgid.link/20230414132415.821564-6-mpe@ellerman.id.au
1 parent 64fcdb2 commit d892ed0

1 file changed

Lines changed: 16 additions & 1 deletion

File tree

arch/powerpc/configs/ppc64_defconfig

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,7 @@ CONFIG_CRASH_DUMP=y
5454
CONFIG_FA_DUMP=y
5555
CONFIG_IRQ_ALL_CPUS=y
5656
CONFIG_SCHED_SMT=y
57+
CONFIG_PPC_SECURE_BOOT=y
5758
CONFIG_VIRTUALIZATION=y
5859
CONFIG_KVM_BOOK3S_64=m
5960
CONFIG_KVM_BOOK3S_64_HV=m
@@ -335,13 +336,25 @@ CONFIG_NLS_CODEPAGE_437=y
335336
CONFIG_NLS_ASCII=y
336337
CONFIG_NLS_ISO8859_1=y
337338
CONFIG_NLS_UTF8=y
339+
CONFIG_SECURITY=y
340+
CONFIG_SECURITY_LOCKDOWN_LSM=y
341+
CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y
342+
CONFIG_INTEGRITY_SIGNATURE=y
343+
CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
344+
CONFIG_INTEGRITY_PLATFORM_KEYRING=y
345+
CONFIG_IMA=y
346+
CONFIG_IMA_KEXEC=y
347+
CONFIG_IMA_DEFAULT_HASH_SHA256=y
348+
CONFIG_IMA_WRITE_POLICY=y
349+
CONFIG_IMA_APPRAISE=y
350+
CONFIG_IMA_ARCH_POLICY=y
351+
CONFIG_IMA_APPRAISE_MODSIG=y
338352
CONFIG_CRYPTO_TEST=m
339353
CONFIG_CRYPTO_BLOWFISH=m
340354
CONFIG_CRYPTO_CAST6=m
341355
CONFIG_CRYPTO_SERPENT=m
342356
CONFIG_CRYPTO_TWOFISH=m
343357
CONFIG_CRYPTO_PCBC=m
344-
CONFIG_CRYPTO_HMAC=y
345358
CONFIG_CRYPTO_MICHAEL_MIC=m
346359
CONFIG_CRYPTO_SHA256=y
347360
CONFIG_CRYPTO_WP512=m
@@ -352,6 +365,8 @@ CONFIG_CRYPTO_SHA1_PPC=m
352365
CONFIG_CRYPTO_DEV_NX=y
353366
CONFIG_CRYPTO_DEV_NX_ENCRYPT=m
354367
CONFIG_CRYPTO_DEV_VMX=y
368+
CONFIG_SYSTEM_TRUSTED_KEYRING=y
369+
CONFIG_SYSTEM_BLACKLIST_KEYRING=y
355370
CONFIG_PRINTK_TIME=y
356371
CONFIG_PRINTK_CALLER=y
357372
CONFIG_DEBUG_KERNEL=y

0 commit comments

Comments
 (0)