Skip to content
  • Roberto Sassu's avatar
    main: added support for loading IMA custom policies · 81611586
    Roberto Sassu authored
    
    
    This is an S/MIME signed message
    
    The new function ima_setup() loads an IMA custom policy from a file in the
    default location '/etc/ima/ima-policy', if present, and writes it to the
    path 'ima/policy' in the security filesystem. This function is executed
    at early stage in order to avoid that some file operations are not measured
    by IMA and it is placed after the initialization of SELinux because IMA
    needs the latter (or other security modules) to understand LSM-specific
    rules. This feature is enabled by default and can be disabled by providing
    the option '--disable-ima' to the configure script.
    
    Signed-off-by: default avatarRoberto Sassu <roberto.sassu@polito.it>
    Acked-by: default avatarGianluca Ramunno <ramunno@polito.it>
    81611586