)]}'
{
  "commit": "56104cf2b8d20eed32c14eac8ac574c35377ab38",
  "tree": "7fc12f22e49f9b799c998245f226906db293255e",
  "parents": [
    "d3bfe84129f65e0af2450743ebdab33d161d01c9"
  ],
  "author": {
    "name": "David Howells",
    "email": "dhowells@redhat.com",
    "time": "Thu Apr 07 09:45:23 2016 +0100"
  },
  "committer": {
    "name": "David Howells",
    "email": "dhowells@redhat.com",
    "time": "Mon Apr 11 22:49:15 2016 +0100"
  },
  "message": "IMA: Use the the system trusted keyrings instead of .ima_mok\n\nAdd a config option (IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY)\nthat, when enabled, allows keys to be added to the IMA keyrings by\nuserspace - with the restriction that each must be signed by a key in the\nsystem trusted keyrings.\n\nEPERM will be returned if this option is disabled, ENOKEY will be returned if\nno authoritative key can be found and EKEYREJECTED will be returned if the\nsignature doesn\u0027t match.  Other errors such as ENOPKG may also be returned.\n\nIf this new option is enabled, the builtin system keyring is searched, as is\nthe secondary system keyring if that is also enabled.  Intermediate keys\nbetween the builtin system keyring and the key being added can be added to\nthe secondary keyring (which replaces .ima_mok) to form a trust chain -\nprovided they are also validly signed by a key in one of the trusted keyrings.\n\nThe .ima_mok keyring is then removed and the IMA blacklist keyring gets its\nown config option (IMA_BLACKLIST_KEYRING).\n\nSigned-off-by: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: Mimi Zohar \u003czohar@linux.vnet.ibm.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "614424029de71b351b4319e6680ea779c5735582",
      "old_mode": 33188,
      "old_path": "include/keys/system_keyring.h",
      "new_id": "fbd4647767e9162f10c5741825796c5c2061cef0",
      "new_mode": 33188,
      "new_path": "include/keys/system_keyring.h"
    },
    {
      "type": "modify",
      "old_id": "98ee4c752cf5dc7214b4ad1349c5b24eb9399da2",
      "old_mode": 33188,
      "old_path": "security/integrity/digsig.c",
      "new_id": "4304372b323f76ac63c632c71c9b0bef7625490d",
      "new_mode": 33188,
      "new_path": "security/integrity/digsig.c"
    },
    {
      "type": "modify",
      "old_id": "e54a8a8dae941f1e2bbff37962184f4f1c84c192",
      "old_mode": 33188,
      "old_path": "security/integrity/ima/Kconfig",
      "new_id": "5487827fa86c7f1b236521dca9d36c1805bfc1f8",
      "new_mode": 33188,
      "new_path": "security/integrity/ima/Kconfig"
    },
    {
      "type": "modify",
      "old_id": "a8539f9e060fe359ebb407136aca3f4fe923c9c1",
      "old_mode": 33188,
      "old_path": "security/integrity/ima/Makefile",
      "new_id": "9aeaedad1e2b9f69e89fa19750490b9ad5cdcc0b",
      "new_mode": 33188,
      "new_path": "security/integrity/ima/Makefile"
    },
    {
      "type": "modify",
      "old_id": "2988726d30d6ca8c5e1ccfb1bc738156d1be0e17",
      "old_mode": 33188,
      "old_path": "security/integrity/ima/ima_mok.c",
      "new_id": "74a2799574642efb845b0eb60ac39c8f19f20b2b",
      "new_mode": 33188,
      "new_path": "security/integrity/ima/ima_mok.c"
    }
  ]
}
