mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Ahmad Fatoum <a.fatoum@pengutronix.de>
To: barebox@lists.infradead.org
Cc: Ahmad Fatoum <a.fatoum@barebox.org>
Subject: [PATCH 03/11] Documentation: security: require signature verification to be pinned
Date: Mon, 28 Sep 2026 13:26:58 +0200	[thread overview]
Message-ID: <20260928112731.1271094-4-a.fatoum@pengutronix.de> (raw)
In-Reply-To: <20260928112731.1271094-1-a.fatoum@pengutronix.de>

From: Ahmad Fatoum <a.fatoum@barebox.org>

global.bootm.verify defaults to "available", which accepts an image that
carries nothing, and "hash" never looks at the configuration signature.

Document that we expect signature to be set and enforced in verified
boot setups.

Signed-off-by: Ahmad Fatoum <a.fatoum@barebox.org>
---
 Documentation/user/security.rst | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index e650c03a1023..7160f8f8e3c2 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -91,6 +91,19 @@ be allowed to boot any images that have not been signed by the correct key.
 This can be enforced by setting ``CONFIG_BOOTM_FORCE_SIGNED_IMAGES=y``
 and disabling any ways that could be used to override this.
 
+How thoroughly an image is checked is controlled by
+:ref:`global.bootm.verify <magicvar_global_bootm_verify>`. Only ``signature``
+is suitable for verified boot. ``hash`` checks the image hashes, but not the
+configuration signature, so it detects corruption, not tampering. The default
+``available`` verifies whatever the image carries and accepts an image
+carrying nothing.
+
+As a global variable, the setting may be changeable at runtime unless barebox
+is built with ``CONFIG_BOOTM_FORCE_SIGNED_IMAGES=y`` or the
+:ref:`security policy <use_security-policies>` denies
+``SCONFIG_BOOT_UNSIGNED_IMAGES``. Either pins it to ``signature``. This
+will also result in :ref:`command_bootm` refusing to boot any non-FIT images.
+
 For development convenience ``CONFIG_CRYPTO_BUILTIN_DEVELOPMENT_KEYS``
 can be enabled after enabling ``CONFIG_INSECURE`` to compile well known
 development keys into the barebox binary.
-- 
2.47.3




  parent reply	other threads:[~2026-09-28 11:29 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 11:26 [PATCH 00/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 02/11] Documentation: security: clarify development key insecurity Ahmad Fatoum
2026-09-28 11:26 ` Ahmad Fatoum [this message]
2026-09-28 11:26 ` [PATCH 04/11] Documentation: security: document trust for builtin devicetree Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 05/11] Documentation: security: clarify the environment section Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 06/11] Documentation: security: describe shell and environment as trust boundary Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 07/11] Documentation: security: document the barebox update attack surface Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 08/11] Documentation: security: update for barebox dm-verity support Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 09/11] Documentation: security: add anchors for the different sections Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 10/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 11/11] README, SECURITY.md: link the threat model and security considerations Ahmad Fatoum

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928112731.1271094-4-a.fatoum@pengutronix.de \
    --to=a.fatoum@pengutronix.de \
    --cc=a.fatoum@barebox.org \
    --cc=barebox@lists.infradead.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox