| Age | Commit message (Expand) | Author | Files | Lines |
| 2023-04-24 | KEYS: Add missing function documentation | Eric Snowberg | 1 | -3/+11 |
| 2023-02-26 | Merge tag 'kbuild-v6.3' of git://git.kernel.org/pub/scm/linux/kernel/git/masa... | Linus Torvalds | 1 | -3/+6 |
| 2023-02-13 | certs: don't try to update blacklist keys | Thomas Weißschuh | 1 | -9/+12 |
| 2023-02-13 | certs: make blacklisted hash available in klog | Thomas Weißschuh | 1 | -1/+1 |
| 2023-01-31 | certs: Fix build error when PKCS#11 URI contains semicolon | Jan Luebbe | 1 | -2/+2 |
| 2023-01-22 | kbuild: do not print extra logs for V=2 | Masahiro Yamada | 1 | -3/+6 |
| 2022-09-24 | certs: make system keyring depend on built-in x509 parser | Masahiro Yamada | 1 | -1/+1 |
| 2022-08-10 | Merge tag 'kbuild-v5.20' of git://git.kernel.org/pub/scm/linux/kernel/git/mas... | Linus Torvalds | 4 | -15/+43 |
| 2022-07-27 | certs: unify blacklist_hashes.c and blacklist_nohashes.c | Masahiro Yamada | 3 | -14/+5 |
| 2022-07-27 | certs: move scripts/check-blacklist-hashes.awk to certs/ | Masahiro Yamada | 2 | -1/+38 |
| 2022-07-24 | certs: make system keyring depend on x509 parser | Adam Borowski | 1 | -0/+1 |
| 2022-06-21 | Merge tag 'certs-20220621' of git://git.kernel.org/pub/scm/linux/kernel/git/d... | Linus Torvalds | 5 | -75/+9 |
| 2022-06-21 | certs: Move load_certificate_list() to be with the asymmetric keys code | David Howells | 5 | -75/+9 |
| 2022-06-15 | certs: fix and refactor CONFIG_SYSTEM_BLACKLIST_HASH_LIST build | Masahiro Yamada | 3 | -12/+12 |
| 2022-06-15 | certs/blacklist_hashes.c: fix const confusion in certs blacklist | Masahiro Yamada | 1 | -1/+1 |
| 2022-06-10 | certs: Convert spaces in certs/Makefile to a tab | David Howells | 1 | -1/+1 |
| 2022-06-08 | cert host tools: Stop complaining about deprecated OpenSSL functions | Linus Torvalds | 1 | -0/+7 |
| 2022-05-26 | Merge tag 'kbuild-v5.19' of git://git.kernel.org/pub/scm/linux/kernel/git/mas... | Linus Torvalds | 1 | -2/+2 |
| 2022-05-23 | certs: Explain the rationale to call panic() | Mickaël Salaün | 1 | -0/+9 |
| 2022-05-23 | certs: Allow root user to append signed hashes to the blacklist keyring | Mickaël Salaün | 2 | -21/+85 |
| 2022-05-23 | certs: Check that builtin blacklist hashes are valid | Mickaël Salaün | 3 | -3/+19 |
| 2022-05-23 | certs: Make blacklist_vet_description() more strict | Mickaël Salaün | 1 | -9/+35 |
| 2022-05-23 | certs: Factor out the blacklist hash creation | Mickaël Salaün | 1 | -18/+58 |
| 2022-04-05 | kbuild: Allow kernel installation packaging to override pkg-config | Chun-Tse Shao | 1 | -2/+2 |
| 2022-03-31 | Merge tag 'kbuild-v5.18-v2' of git://git.kernel.org/pub/scm/linux/kernel/git/... | Linus Torvalds | 2 | -29/+11 |
| 2022-03-08 | KEYS: Introduce link restriction for machine keys | Eric Snowberg | 1 | -1/+34 |
| 2022-03-08 | KEYS: store reference to machine keyring | Eric Snowberg | 1 | -0/+9 |
| 2022-03-03 | certs: simplify empty certs creation in certs/Makefile | Masahiro Yamada | 1 | -10/+11 |
| 2022-03-03 | certs: include certs/signing_key.x509 unconditionally | Masahiro Yamada | 2 | -19/+0 |
| 2022-01-23 | certs: Fix build error when CONFIG_MODULE_SIG_KEY is empty | Masahiro Yamada | 1 | -1/+1 |
| 2022-01-23 | certs: Fix build error when CONFIG_MODULE_SIG_KEY is PKCS#11 URI | Masahiro Yamada | 1 | -1/+1 |
| 2022-01-08 | certs: move scripts/extract-cert to certs/ | Masahiro Yamada | 3 | -4/+172 |
| 2022-01-08 | kbuild: do not quote string values in include/config/auto.conf | Masahiro Yamada | 1 | -8/+2 |
| 2022-01-08 | certs: simplify $(srctree)/ handling and remove config_filename macro | Masahiro Yamada | 1 | -19/+13 |
| 2022-01-08 | certs: remove misleading comments about GCC PR | Masahiro Yamada | 1 | -2/+0 |
| 2022-01-08 | certs: refactor file cleaning | Masahiro Yamada | 1 | -4/+5 |
| 2022-01-08 | certs: remove unneeded -I$(srctree) option for system_certificates.o | Masahiro Yamada | 1 | -3/+0 |
| 2022-01-08 | certs: unify duplicated cmd_extract_certs and improve the log | Masahiro Yamada | 1 | -6/+3 |
| 2022-01-08 | certs: use $< and $@ to simplify the key generation rule | Masahiro Yamada | 1 | -3/+2 |
| 2021-12-11 | certs: use if_changed to re-generate the key when the key type is changed | Masahiro Yamada | 1 | -24/+6 |
| 2021-12-11 | certs: use 'cmd' to hide openssl output in silent builds more simply | Masahiro Yamada | 1 | -6/+6 |
| 2021-12-11 | certs: remove noisy messages while generating the signing key | Masahiro Yamada | 1 | -11/+0 |
| 2021-12-11 | certs: check-in the default x509 config file | Masahiro Yamada | 2 | -18/+23 |
| 2021-12-11 | certs: remove meaningless $(error ...) in certs/Makefile | Masahiro Yamada | 1 | -3/+0 |
| 2021-12-11 | certs: move the 'depends on' to the choice of module signing keys | Masahiro Yamada | 1 | -3/+1 |
| 2021-08-23 | certs: Add support for using elliptic curve keys for signing modules | Stefan Berger | 2 | -0/+39 |
| 2021-08-23 | certs: Trigger creation of RSA module signing key if it's not an RSA key | Stefan Berger | 1 | -0/+8 |
| 2021-05-08 | Merge tag 'kbuild-v5.13-2' of git://git.kernel.org/pub/scm/linux/kernel/git/m... | Linus Torvalds | 1 | -2/+2 |
| 2021-05-01 | Merge tag 'integrity-v5.13' of git://git.kernel.org/pub/scm/linux/kernel/git/... | Linus Torvalds | 4 | -4/+47 |
| 2021-05-02 | .gitignore: prefix local generated files with a slash | Masahiro Yamada | 1 | -2/+2 |
| 2021-04-26 | ima: ensure IMA_APPRAISE_MODSIG has necessary dependencies | Nayna Jain | 3 | -2/+5 |
| 2021-04-26 | certs: add 'x509_revocation_list' to gitignore | Linus Torvalds | 1 | -0/+1 |
| 2021-04-09 | ima: enable loading of build time generated key on .ima keyring | Nayna Jain | 2 | -11/+52 |
| 2021-04-09 | ima: enable signing of modules with build time generated key | Nayna Jain | 2 | -1/+9 |
| 2021-03-11 | certs: Add ability to preload revocation certs | Eric Snowberg | 4 | -2/+67 |
| 2021-03-11 | certs: Move load_system_certificate_list to a common function | Eric Snowberg | 4 | -47/+70 |
| 2021-03-11 | certs: Add EFI_CERT_X509_GUID support for dbx entries | Eric Snowberg | 4 | -0/+60 |
| 2021-01-21 | certs: Replace K{U,G}IDT_INIT() with GLOBAL_ROOT_{U,G}ID | Mickaël Salaün | 2 | -4/+5 |
| 2021-01-21 | certs: Fix blacklist flag type confusion | David Howells | 1 | -1/+1 |
| 2021-01-21 | certs: Fix blacklisted hexadecimal hash string check | Mickaël Salaün | 1 | -1/+1 |
| 2021-01-21 | certs/blacklist: fix kernel doc interface issue | Alex Shi | 1 | -1/+1 |
| 2020-03-25 | .gitignore: add SPDX License Identifier | Masahiro Yamada | 1 | -0/+1 |
| 2020-03-25 | .gitignore: remove too obvious comments | Masahiro Yamada | 1 | -3/+0 |
| 2019-11-12 | certs: Add wrapper function to check blacklisted binary hash | Nayna Jain | 1 | -0/+9 |
| 2019-08-05 | PKCS#7: Refactor verify_pkcs7_signature() | Thiago Jung Bauermann | 1 | -16/+45 |
| 2019-07-10 | Revert "Merge tag 'keys-acl-20190703' of git://git.kernel.org/pub/scm/linux/k... | Linus Torvalds | 2 | -5/+14 |
| 2019-07-08 | Merge tag 'keys-acl-20190703' of git://git.kernel.org/pub/scm/linux/kernel/gi... | Linus Torvalds | 2 | -14/+5 |
| 2019-07-08 | Merge tag 'keys-namespace-20190627' of git://git.kernel.org/pub/scm/linux/ker... | Linus Torvalds | 1 | -1/+1 |
| 2019-06-27 | keys: Replace uid/gid/perm permissions checking with an ACL | David Howells | 2 | -14/+5 |
| 2019-06-26 | keys: Add a 'recurse' flag for keyring searches | David Howells | 1 | -1/+1 |
| 2019-05-24 | treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 36 | Thomas Gleixner | 2 | -10/+2 |
| 2019-02-04 | kexec, KEYS: Make use of platform keyring for signature verify | Kairui Song | 1 | -1/+12 |
| 2019-02-04 | integrity, KEYS: add a reference to platform keyring | Kairui Song | 1 | -0/+10 |
| 2019-01-06 | kbuild: remove redundant target cleaning on failure | Masahiro Yamada | 1 | -1/+1 |
| 2018-08-22 | export.h: remove VMLINUX_SYMBOL() and VMLINUX_SYMBOL_STR() | Masahiro Yamada | 1 | -8/+8 |
| 2018-08-16 | Replace magic for trusting the secondary keyring with #define | Yannik Sembritzki | 1 | -1/+2 |
| 2018-06-26 | certs/blacklist: fix const confusion | Nick Desaulniers | 1 | -1/+1 |
| 2018-06-15 | docs: Fix some broken references | Mauro Carvalho Chehab | 1 | -1/+1 |
| 2018-02-21 | certs/blacklist_nohashes.c: fix const confusion in certs blacklist | Andi Kleen | 1 | -1/+1 |
| 2017-11-02 | License cleanup: add SPDX GPL-2.0 license identifier to files with no license | Greg Kroah-Hartman | 5 | -0/+5 |
| 2017-07-14 | modsign: add markers to endif-statements in certs/Makefile | Jarkko Sakkinen | 1 | -3/+3 |
| 2017-05-08 | scripts/spelling.txt: add "intialise(d)" pattern and fix typo instances | Masahiro Yamada | 1 | -1/+1 |
| 2017-04-04 | KEYS: Use structure to capture key restriction function and data | Mat Martineau | 1 | -1/+20 |
| 2017-04-03 | KEYS: Split role of the keyring pointer for keyring restrict functions | Mat Martineau | 1 | -7/+11 |
| 2017-04-03 | KEYS: Add a system blacklist keyring | David Howells | 6 | -0/+212 |
| 2016-04-11 | certs: Add a secondary system keyring that can be added to dynamically | David Howells | 2 | -16/+79 |
| 2016-04-11 | KEYS: Remove KEY_FLAG_TRUSTED and KEY_ALLOC_TRUSTED | David Howells | 1 | -2/+0 |
| 2016-04-11 | KEYS: Move the point of trust determination to __key_link() | David Howells | 1 | -3/+17 |
| 2016-04-11 | KEYS: Make the system trusted keyring depend on the asymmetric key type | David Howells | 1 | -0/+1 |
| 2016-04-11 | KEYS: Add a facility to restrict new links into a keyring | David Howells | 1 | -4/+4 |
| 2016-04-06 | PKCS#7: Make trust determination dependent on contents of trust keyring | David Howells | 1 | -9/+4 |
| 2016-04-06 | KEYS: Generalise system_verify_data() to provide access to internal content | David Howells | 1 | -10/+35 |
| 2016-02-29 | certs: Fix misaligned data in extra certificate list | David Howells | 1 | -0/+1 |
| 2016-02-26 | KEYS: Reserve an extra certificate symbol for inserting without recompiling | Mehmet Kayaalp | 2 | -0/+28 |
| 2016-02-26 | modsign: hide openssl output in silent builds | Arnd Bergmann | 1 | -14/+19 |
| 2016-02-09 | KEYS: Add an alloc flag to convey the builtinness of a key | David Howells | 1 | -2/+2 |
| 2015-10-21 | certs: add .gitignore to stop git nagging about x509_certificate_list | Paul Gortmaker | 1 | -0/+4 |
| 2015-08-14 | modsign: Handle signing key in source tree | David Woodhouse | 1 | -54/+0 |
| 2015-08-14 | modsign: Use if_changed rule for extracting cert from module signing key | David Woodhouse | 1 | -2/+3 |
| 2015-08-14 | Move certificate handling to its own directory | David Howells | 4 | -0/+369 |