ima: Remove deprecated IMA_TRUSTED_KEYRING Kconfig
authorNayna Jain <nayna@linux.ibm.com>
Tue, 11 Jul 2023 16:44:47 +0000 (12:44 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 13 Sep 2023 07:42:42 +0000 (09:42 +0200)
[ Upstream commit 5087fd9e80e539d2163accd045b73da64de7de95 ]

Time to remove "IMA_TRUSTED_KEYRING".

Fixes: f4dc37785e9b ("integrity: define '.evm' as a builtin 'trusted' keyring") # v4.5+
Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
security/integrity/ima/Kconfig

index 60a511c..c17660b 100644 (file)
@@ -248,18 +248,6 @@ config IMA_APPRAISE_MODSIG
           The modsig keyword can be used in the IMA policy to allow a hook
           to accept such signatures.
 
-config IMA_TRUSTED_KEYRING
-       bool "Require all keys on the .ima keyring be signed (deprecated)"
-       depends on IMA_APPRAISE && SYSTEM_TRUSTED_KEYRING
-       depends on INTEGRITY_ASYMMETRIC_KEYS
-       select INTEGRITY_TRUSTED_KEYRING
-       default y
-       help
-          This option requires that all keys added to the .ima
-          keyring be signed by a key on the system trusted keyring.
-
-          This option is deprecated in favor of INTEGRITY_TRUSTED_KEYRING
-
 config IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY
        bool "Permit keys validly signed by a built-in or secondary CA cert (EXPERIMENTAL)"
        depends on SYSTEM_TRUSTED_KEYRING