From: Petr Vorel Date: Thu, 4 Apr 2019 18:23:22 +0000 (+0200) Subject: doc/kernel-parameters.txt: Deprecate ima_appraise_tcb X-Git-Tag: v5.2-rc1~112^2^2 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=41475a3ebaceb270e47a77356ddc30960354cb00;p=thirdparty%2Fkernel%2Flinux.git doc/kernel-parameters.txt: Deprecate ima_appraise_tcb Signed-off-by: Petr Vorel Signed-off-by: Mimi Zohar --- diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt index 2b8ee90bb6447..45147fc40a57a 100644 --- a/Documentation/admin-guide/kernel-parameters.txt +++ b/Documentation/admin-guide/kernel-parameters.txt @@ -1585,7 +1585,7 @@ Format: { "off" | "enforce" | "fix" | "log" } default: "enforce" - ima_appraise_tcb [IMA] + ima_appraise_tcb [IMA] Deprecated. Use ima_policy= instead. The builtin appraise policy appraises all files owned by uid=0. @@ -1612,8 +1612,7 @@ uid=0. The "appraise_tcb" policy appraises the integrity of - all files owned by root. (This is the equivalent - of ima_appraise_tcb.) + all files owned by root. The "secure_boot" policy appraises the integrity of files (eg. kexec kernel image, kernel modules,