mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
Add kernel module phmac_s390 to the initramfs hook and dracut config file to ensure that the PHMAC cipher is available during early boot, in case the root disk is integrity protected via PHMAC. Also load phmac_s390 via modules-load.d to ensure that the PHMAC ciphers are available. Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Reviewed-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
48 lines
988 B
Bash
48 lines
988 B
Bash
#!/bin/sh
|
|
#
|
|
# Copyright IBM Corp. 2022
|
|
# Copyright Canonical Ltd 2018
|
|
#
|
|
# s390-tools is free software; you can redistribute it and/or modify
|
|
# it under the terms of the MIT license. See LICENSE for details.
|
|
#
|
|
# hooks/s390-tools-zkey
|
|
# This hook script adds zkey related utilities and zkey repository
|
|
# in the initramfs
|
|
#
|
|
|
|
# Needs to run after udev or resulting udev rules could be overwritten
|
|
PREREQ="udev"
|
|
|
|
prereqs()
|
|
{
|
|
echo "$PREREQ"
|
|
}
|
|
|
|
case $1 in
|
|
prereqs)
|
|
prereqs
|
|
exit 0
|
|
;;
|
|
esac
|
|
|
|
. /usr/share/initramfs-tools/hook-functions
|
|
|
|
# Add zcrypt modules
|
|
zdev_modules="uvdevice pkey pkey_cca pkey_ep11 pkey_pckmo pkey_uv paes_s390 phmac_s390 zcrypt zcrypt_cex4"
|
|
|
|
for x in $zdev_modules ; do
|
|
manual_add_modules ${x}
|
|
done
|
|
|
|
# copy utils
|
|
copy_exec /sbin/chzcrypt
|
|
copy_exec /sbin/lszcrypt
|
|
copy_exec /usr/bin/zkey
|
|
copy_exec /usr/bin/zkey-cryptsetup
|
|
copy_exec /usr/lib64/zkey/zkey-ekmfweb.so
|
|
copy_exec /usr/lib64/zkey/zkey-kmip.so
|
|
|
|
mkdir -p "${DESTDIR}/etc"
|
|
cp -a /etc/zkey "${DESTDIR}/etc/"
|