mirror of
https://github.com/flatcar/scripts.git
synced 2026-05-04 11:51:14 +02:00
sys-kernel/coreos-modules: Enable lockdown when booted with secure boot
This is a requirement of the shim signing process. Signed-off-by: Jeremi Piotrowski <jpiotrowski@microsoft.com>
This commit is contained in:
parent
8393a4cf4b
commit
580c181df8
@ -422,6 +422,7 @@ CONFIG_LEDS_CLASS=y
|
||||
CONFIG_LIBFC=m
|
||||
CONFIG_LIBFCOE=m
|
||||
# CONFIG_LOCALVERSION_AUTO is not set
|
||||
CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y
|
||||
CONFIG_LOG_BUF_SHIFT=18
|
||||
CONFIG_LOOPBACK_TARGET=m
|
||||
CONFIG_LSM="landlock,lockdown,yama,loadpin,safesetid,integrity,selinux,smack,tomoyo,apparmor"
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user