Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-8824

Unable to use imported IMA key on self-signed RPM.

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-9.1.0
    • ima-evm-utils
    • None
    • Moderate
    • rhel-sst-kernel-security
    • ssg_core_kernel
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      Description of problem:
      When configuring IMA/EVM and importing a key to the IMA keyring, while the key can be successfully imported, said key is unable to be used with any self-signed RPM packages that has the key's respective certificate.

      Version-Release number of selected component (if applicable):
      libattr-2.5.1-3.el9.x86_64
      attr-2.5.1-3.el9.x86_64
      ima-evm-utils-1.4-4.el9.x86_64
      keyutils-libs-1.6.3-1.el9.x86_64
      keyutils-1.6.3-1.el9.x86_64

      How reproducible:
      Consistently

      Steps to Reproduce:
      1. Implement IMA/EVM via documentation (see Additional Info).
      2. Create key and respective self-signed certificate.
      3. Create RPM package and sign with certificate.
      4. Import key to IMA keyring.
      5. Attempt to install self-signed RPM.

      Actual results:
      Imported key is able to be utilized on it's respective self-signed RPM package.

      Expected results:
      Imported key is unable to be utilized on it's respective self-signed RPM package.

      Additional info:
      Documentation referenced is the following:

      https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/managing_monitoring_and_updating_the_kernel/enhancing-security-with-the-kernel-integrity-subsystem_managing-monitoring-and-updating-the-kernel#enabling-integrity-measurement-architecture-and-extended-verification-module_enhancing-security-with-the-kernel-integrity-subsystem

              coxu@redhat.com Coiby Xu
              brclark@redhat.com Brandon Clark
              Coiby Xu Coiby Xu
              Linqing Lu Linqing Lu
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: