From c9d9c5a37e289235f8897d43c5c4f1dcfc5e7a90 Mon Sep 17 00:00:00 2001 From: Josh Boyer Date: Fri, 30 Aug 2013 11:32:36 -0400 Subject: Rework Secure Boot support to use the secure_modules approach - Drop pekey --- config-x86-generic | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) (limited to 'config-x86-generic') diff --git a/config-x86-generic b/config-x86-generic index f2a071e3f..64f5a2fc8 100644 --- a/config-x86-generic +++ b/config-x86-generic @@ -441,14 +441,14 @@ CONFIG_VMWARE_VMCI_VSOCKETS=m CONFIG_XZ_DEC_X86=y CONFIG_MPILIB=y -CONFIG_PKCS7_MESSAGE_PARSER=y -CONFIG_PE_FILE_PARSER=y CONFIG_MODULE_SIG=y CONFIG_MODULE_SIG_ALL=y # CONFIG_MODULE_SIG_SHA1 is not set CONFIG_MODULE_SIG_SHA256=y # CONFIG_MODULE_SIG_FORCE is not set -CONFIG_SYSTEM_BLACKLIST_KEYRING=y +CONFIG_MODULE_SIG_BLACKLIST=y +CONFIG_EFI_SECURE_BOOT_SIG_ENFORCE=y +CONFIG_EFI_SIGNATURE_LIST_PARSER=y CONFIG_MODULE_SIG_UEFI=y -- cgit