On 11/14/2019 6:37 AM, Mimi Zohar wrote:
Keyrings may be created by userspace with any name (e.g. foo, foobar, ...). A keyring name might be a subset of another keyring name. For example, with the policy "keyrings=foobar", keys being loaded on "foo" would also be measured. Using strstr() will not achieve what is needed. Mimi
Very good catch - I missed that :( Will fix and send an update. thanks, -lakshmi