Commit d0d5a2c
committed
redhat: hmac sign the UKI for FIPS
JIRA: INTERNAL
Upstream Status: RHEL-only
ARK commit: c21494f10acecd92677eb363b38956a4994b2e29
Dracut's FIPS module contains kernel integrity check for traditional
kernels: /boot/vmlinuz-`uname-r`'s HMAC is compared to
/boot/.vmlinuz-`uname-r`.hmac which is created duing kernel
build. In preparation to enabling FIPS mode support for UKI, create
HMAC for the it too.
Signed-off-by: Vitaly Kuznetsov <vkuznets@redhat.com>1 parent 03685f4 commit d0d5a2c
1 file changed
+7
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2511 | 2511 | | |
2512 | 2512 | | |
2513 | 2513 | | |
| 2514 | + | |
| 2515 | + | |
| 2516 | + | |
| 2517 | + | |
| 2518 | + | |
| 2519 | + | |
2514 | 2520 | | |
2515 | 2521 | | |
2516 | 2522 | | |
| |||
3727 | 3733 | | |
3728 | 3734 | | |
3729 | 3735 | | |
| 3736 | + | |
3730 | 3737 | | |
3731 | 3738 | | |
3732 | 3739 | | |
| |||
0 commit comments