mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-09-03 18:04:16 +00:00
gpu: Add proper config for module signing
We want to enable module signing in Kata and Coco Signed-off-by: Zvonko Kaiser <zkaiser@nvidia.com>
This commit is contained in:
@@ -7,9 +7,6 @@ CONFIG_PCI_MMCONFIG=y
|
|||||||
CONFIG_MODULES=y
|
CONFIG_MODULES=y
|
||||||
CONFIG_MODULE_UNLOAD=y
|
CONFIG_MODULE_UNLOAD=y
|
||||||
|
|
||||||
# CRYPTO_FIPS requires this config when loading modules is enabled.
|
|
||||||
CONFIG_MODULE_SIG=y
|
|
||||||
|
|
||||||
# Linux kernel version suffix
|
# Linux kernel version suffix
|
||||||
CONFIG_LOCALVERSION="-nvidia-gpu${CONF_GUEST_SUFFIX}"
|
CONFIG_LOCALVERSION="-nvidia-gpu${CONF_GUEST_SUFFIX}"
|
||||||
|
|
||||||
@@ -25,3 +22,11 @@ CONFIG_X86_PAT=y
|
|||||||
CONFIG_CRYPTO_ECC=y
|
CONFIG_CRYPTO_ECC=y
|
||||||
CONFIG_CRYPTO_ECDH=y
|
CONFIG_CRYPTO_ECDH=y
|
||||||
CONFIG_CRYPTO_ECDSA=y
|
CONFIG_CRYPTO_ECDSA=y
|
||||||
|
|
||||||
|
# Module signing
|
||||||
|
CONFIG_MODULE_SIG=y
|
||||||
|
CONFIG_MODULE_SIG_FORCE=y
|
||||||
|
CONFIG_MODULE_SIG_ALL=y
|
||||||
|
CONFIG_MODULE_SIG_SHA512=y
|
||||||
|
CONFIG_SYSTEM_TRUSTED_KEYS=""
|
||||||
|
CONFIG_SYSTEM_TRUSTED_KEYRING=y
|
||||||
|
Reference in New Issue
Block a user