Commit 579b2ba
dm verity: fallback to platform keyring also if key in trusted keyring is rejected
If enabled, we fallback to the platform keyring if the trusted keyring doesn't have
the key used to sign the roothash. But if pkcs7_verify() rejects the key for other
reasons, such as usage restrictions, we do not fallback. Do so.
Follow-up for 6fce1f4
Suggested-by: Serge Hallyn <[email protected]>
Signed-off-by: Luca Boccassi <[email protected]>
Acked-by: Jarkko Sakkinen <[email protected]>
Signed-off-by: Mikulas Patocka <[email protected]>1 parent e6a3531 commit 579b2ba
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
| 130 | + | |
131 | 131 | | |
132 | 132 | | |
133 | 133 | | |
| |||
0 commit comments