From a460debc8ea366c0c706de3b71e2c6ff56988791 Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Sat, 12 Nov 2022 01:07:13 +0000 Subject: README: note Kconfig for verifying DDIs via MoK keys Also note them in the mkosi.build kernel config list --- mkosi.build | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'mkosi.build') diff --git a/mkosi.build b/mkosi.build index cbf82811cf..70721a88a3 100755 --- a/mkosi.build +++ b/mkosi.build @@ -307,6 +307,10 @@ if [ -d mkosi.kernel/ ]; then --enable MEMCG \ --enable MEMCG_SWAP \ --enable MEMCG_KMEM \ + --enable IMA_ARCH_POLICY \ + --enable DM_VERITY_VERIFY_ROOTHASH_SIG \ + --enable DM_VERITY_VERIFY_ROOTHASH_SIG_SECONDARY_KEYRING \ + --enable INTEGRITY_MACHINE_KEYRING \ --enable NETFILTER_ADVANCED \ --enable NF_CONNTRACK_MARK -- cgit v1.2.1