From 7d7036764ffaf151a6bf0bfafa20ff79dad49c2c Mon Sep 17 00:00:00 2001 From: Brian Kress Date: Sun, 29 Mar 2026 10:17:25 -0400 Subject: [PATCH] feat: Allow the kernel to verify modules with MOK key --- config | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/config b/config index 8eb8e39..e9e8578 100644 --- a/config +++ b/config @@ -11603,8 +11603,9 @@ CONFIG_INTEGRITY_MACHINE_KEYRING=y # CONFIG_INTEGRITY_CA_MACHINE_KEYRING is not set CONFIG_LOAD_UEFI_KEYS=y CONFIG_INTEGRITY_AUDIT=y -# CONFIG_IMA is not set -# CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set +CONFIG_IMA=y +CONFIG_IMA_ARCH_POLICY=y +CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT=y # CONFIG_EVM is not set CONFIG_DEFAULT_SECURITY_SELINUX=y # CONFIG_DEFAULT_SECURITY_SMACK is not set