# Enable bare minimum IMA measurement and appraisal as needed by this layer. CONFIG_SECURITY=y CONFIG_INTEGRITY=y # measurement CONFIG_IMA=y # appraisal CONFIG_IMA_APPRAISE=y CONFIG_INTEGRITY_SIGNATURE=y CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y # Kernel will get built with embedded X.509 root CA key and all keys # need to be signed with that. CONFIG_IMA_TRUSTED_KEYRING=y