summaryrefslogtreecommitdiffstats
path: root/system/ima-evm-utils/README
blob: ec9deccf9b5d8a9738b07f3f1cf6651e154c805c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
Linux kernel integrity subsystem is comprised of a number of different
components including the Integrity Measurement Architecture (IMA),
Extended Verification Module (EVM), IMA-appraisal extension, digital
signature verification extension and audit measurement log support.

The evmctl utility is used for producing and verifying digital
signatures, which are used by the Linux kernel integrity subsystem. It
is also used for importing keys into the kernel keyring.

Linux integrity subsystem allows to use IMA and EVM signatures. EVM
signature protects file metadata, such as file attributes and extended
attributes. IMA signature protects file content.