Enable BPF program signing support - #93
Open
dylandreimerink wants to merge 2 commits into
Open
Conversation
BPF program signing support is gated by the kernel configuration option `CONFIG_SYSTEM_DATA_VERIFICATION`. This kconfig is hidden, only enabled when other kconfigs that depend on it are enabled. Enabling `CONFIG_FS_VERITY` and `CONFIG_FS_VERITY_BUILTIN_SIGNATURES` seemed to be the best way to enable support without to much side effects. Signed-off-by: Dylan Reimerink <dylan.reimerink@isovalent.com>
This commit enables RSA, ECDSA, and MLDSA signing algorithms as well as SHA256, SHA512, and SHA3 hashing algorithms in the kernel configuration. Enabling these in the kernel to allow verification of different signature types for BPF programs. Signed-off-by: Dylan Reimerink <dylan.reimerink@isovalent.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
BPF program signing support is gated by the kernel configuration option
CONFIG_SYSTEM_DATA_VERIFICATION. This kconfig is hidden, only enabled when other kconfigs that depend on it are enabled.Enabling
CONFIG_FS_VERITYandCONFIG_FS_VERITY_BUILTIN_SIGNATURESseemed to be the best way to enable support without to much side effects.This PR also enables some additional crypto algorithms for signing and hashing which allows us to test that signing works with multiple modern signing and hashing algorithms.