From: Mimi Zohar Date: Tue, 20 Aug 2013 18:36:27 +0000 (-0400) Subject: KEYS: verify a certificate is signed by a 'trusted' key X-Git-Tag: omap-for-v3.17/fixes-against-rc2~151^2~12^2~1^2~4 X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3be4beaf7c91ec9c6fefa5f11173af37113d10ae;p=pandora-kernel.git KEYS: verify a certificate is signed by a 'trusted' key Only public keys, with certificates signed by an existing 'trusted' key on the system trusted keyring, should be added to a trusted keyring. This patch adds support for verifying a certificate's signature. This is derived from David Howells pkcs7_request_asymmetric_key() patch. Changelog v6: - on error free key - Dmitry - validate trust only for not already trusted keys - Dmitry - formatting cleanup Changelog: - define get_system_trusted_keyring() to fix kbuild issues Signed-off-by: Mimi Zohar Signed-off-by: David Howells Acked-by: Dmitry Kasatkin --- Reading git-diff-tree failed