aboutsummaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)Author
2019-08-09ima: remove kernel fragments now in cachewip_kernelArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-09linux-stable/5.2: add stable bbappendArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-09linux-%: remove kernel fragments now in cacheArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-07layer.conf: switch to keyutils from meta-oeDmitry Eremin-Solenikov
As pointer by Martin Jansa, keyutils package is now a part of meta-oe, so switch to using keyutils from that layer. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-07scap-security-guide: fix typoYi Zhao
Fix typo: RDEPNEDS_${PN} -> RDEPENDS_${PN} Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-07openscap: cleanup DEPENDSYi Zhao
Remove autoconf-archive from DEPENDS because it is using CMake/Ninjia build now. Also remove unused dpkg-native dependency from DEPENDS_class-native. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-07linux: add support for kernel modules signingDmitry Eremin-Solenikov
Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>
2019-08-07kernel-modsign.bbclass: add support for kernel modules signingDmitry Eremin-Solenikov
Add bbclass responsible for handling signing of kernel modules. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> fixup class to avoid including in every configure task Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04ima-evm-utils: bump to release 1.2.1Dmitry Eremin-Solenikov
Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04meta-integrity: rename IMA_EVM_BASE to INTEGRITY_BASEDmitry Eremin-Solenikov
data/debug-keys will be reused for demo modsign keys, so rename IMA_EVM_BASE to more generic INTEGRITY_BASE. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com>
2019-08-04scap-security-guide: update recipeYi Zhao
* Set B="${S}/build" to fix the build failure for out of source directory * Remove do_complile and do_install. Use the default functions from cmake.bbclass. * Install the artifacts to /usr/share rather than /usr/local/share Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04openscap: update recipeYi Zhao
* Add PACKAGECONFIG for gcrypt, nss3 and selinux * Use EXTRA_OECMAKE rather than EXTRA_OECONF * Set CMAKE_SKIP_RPATH and CMAKE_SKIP_INSTALL_RPATH instead of chrpath * Remove ptest since there are many host contamination issues on target. We will add it back when these issues are solved. * Drop the unused patch * Add PV Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04tpm2-tcti-uefi: build and install examplesDmitry Eremin-Solenikov
Examples are usefull to actually check TPM2 from UEFI shell. Add them to tpm2-tcti-uefi package. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04tpm2-tcti-uefi: stop inserting host directories into build pathDmitry Eremin-Solenikov
Do not insert /usr/lib and /usr/lib64 into LDFLAGS. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04tpm2-tcti-uefi: fix configure argumentsDmitry Eremin-Solenikov
Pass correct location of EFI's crt0 and ld script. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04tpm2-tcti-uefi: add autoconf-archive-native dependencyDmitry Eremin-Solenikov
Add dependency on autoconf-archive-native to receive AX_* macro definitions. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04tpm2-tss: fix compilation when using updated AX_CODE_COVERAGE macroDmitry Eremin-Solenikov
New autoconf-archive comes with updated AX_CODE_COVERAGE macro, which is not compatible with current tpm2-tss source base. Apply upstream patch to fix this incompatibility. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04packagegroup-security-tpm2: stop including tpm2-tcti-uefiDmitry Eremin-Solenikov
tpm2-tcti-uefi is a EFI module, so it should not be included in the rootfs. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04ima-evm-utils: refresh xattr patchlumag
Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04ima-evm-utils: bump versionlumag
Currently selected SRCREV (782224f33cd711050cbf6146a12122cd73f9136b) comes after 1.1 ima-evm-utils release, so bump PV accordingly. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04layer.conf: add dependency on meta-securitylumag
ima-evm-utils recipe depends on keyutils recipe which is a part of meta-security layer. Signed-off-by: Dmitry Eremin-Solenikov <dmitry_eremin-solenikov@mentor.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04keyutils: remove from meta-securityArmin Kuster
now in meta-oe Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04samhain: update to 4.3.3Armin Kuster
remove PV from recipes names to make package update easier. PV set in include file now drop samhain-cross-compile.patch as stripping appears to have been removed. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04waf-cross-answers: remove filesArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-08-04libldb: remove recipeArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-17meta-security-compliance: add meta-pythonArmin Kuster
with some for the recipe updates, more pyton support is needed Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-17scap-security-guide: update to 0.1.44Armin Kuster
create a PV version to track upstream git version includes OE changes Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-17openscap: add 1.3.1 recipes for upstream sourceArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-17openscap_git: update to 1.3.0Armin Kuster
removed unneeded patch convert over to cmake refactor files Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-07openscap/scap-security-guide: use _git instead of versioned filenamesMark Asselstine
In order to facilate the reuse of the recipe code via layer or distro specific bbappends rename the recipe files to use _git instead of versined filenames. Specifically this allows for minimal bbappends in additional layers which may use the upstream, non-forked, repos that can be version skewed when compared to what is present in this repo. Signed-off-by: Mark Asselstine <mark.asselstine@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-07meta-security-compliance: update READMEArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-07-07lynis: update to 2.7.5Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26kernel: Add conditional inclusion of fragments for linux-yocto-devHe Zhe
Signed-off-by: He Zhe <zhe.he@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26clamav: minor recipe cleanupArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26libmspack: update SRC_URI and packageArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-tss-engine: update to 1.0.0Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-totp: update to offical release v0.1.1Armin Kuster
Clean up recipe to match actual app Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-tss: update to 2.2.3Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-tools: update to 3.2.0Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-tcti-uefi: update to tipArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2-pkcs11/tpm2-pkcs11: update to tipArmin Kuster
license-check-sum: Add SPDX format Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm image: split out tpm2Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26tpm2 images: create tpm2 image and fix packagegroupArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26runtime: tpm2 fix names in packagecheckArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26ima-evm-utils: update to tipArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26test-image: add a few more packages to imageArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26test-image: add packagegroup-core-security-ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26packagegroup-core-security: cleanup and remove ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26runtime: clamav test cleanupArmin Kuster
mirror test is independant of download Signed-off-by: Armin Kuster <akuster808@gmail.com>
2019-06-26security-test-image: add a testing imageArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>