IMA Measured Boot¶
About This Task¶
The Integrity Measurement Architecture (IMA) measures files as they are executed or loaded, stores the hashes in the kernel, and extends PCR 10. Use this procedure to inspect the IMA securityfs interface, load the default measurement policy if none is active, and view the runtime measurement list.
For background on the Integrity Measurement Architecture and its policy syntax, see the following external resources:
Before You Begin¶
You must have a running eLxr bianca system with a TPM 2.0 device available. For a test environment, see Setting Up a Test Environment with QEMU/KVM.
The default IMA measurement policy is shipped with the image package at /etc/ima/ima-policy-remote-attestation.
Procedure¶
List the IMA securityfs interface.
$ ls /sys/kernel/security/ima/
Expected entries include policy, ascii_runtime_measurements, and runtime_measurements_count.
If no policy is active after boot, load the default policy shipped with the image.
$ sudo cat /etc/ima/ima-policy-remote-attestation > /sys/kernel/security/ima/policy
View the IMA runtime measurement list.
$ sudo cat /sys/kernel/security/ima/ascii_runtime_measurements | head
The runtime measurement list is the kernel’s running record of every file IMA has hashed since boot. Each time a covered file is executed or loaded, IMA computes its hash, appends an entry to this list, and extends PCR 10 with that hash. The list grows as the system runs, so it reflects exactly what has been loaded and the order in which it happened.
Each line records one measured file in the following fields:
PCR template-hash template file-hash filename
The PCR field is the register the entry extends, normally 10. The template-hash is the hash of the entry as a whole, which is the value folded into the PCR. The template names the format of the remaining fields. The file-hash is the hash of the file’s contents, and filename is the path that was measured. Because each file-hash is a fixed record of the content at the moment it was loaded, comparing these values against a set of approved hashes reveals whether anything unexpected ran on the system.
Results¶
IMA is measuring files as they are loaded and extending PCR 10 with the measurement list. These measurements can be included in a TPM quote for Remote Attestation.