|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] vTPM Manager shuts down
On 05/23/2013 10:35 AM, Ross Philipson wrote: -----Original Message----- From: Konrad Rzeszutek Wilk [mailto:konrad.wilk@xxxxxxxxxx] Sent: Wednesday, May 22, 2013 4:54 PM To: Ross Philipson Cc: Daniel De Graaf; Jordi Cucurull Juan; xen-devel@xxxxxxxxxxxxx Subject: Re: [Xen-devel] vTPM Manager shuts down On Wed, May 22, 2013 at 07:14:04PM +0000, Ross Philipson wrote:-----Original Message----- From: xen-devel-bounces@xxxxxxxxxxxxx [mailto:xen-devel- bounces@xxxxxxxxxxxxx] On Behalf Of Ross Philipson Sent: Wednesday, May 22, 2013 3:06 PM To: Konrad Rzeszutek Wilk; Daniel De Graaf Cc: Jordi Cucurull Juan; xen-devel@xxxxxxxxxxxxx Subject: Re: [Xen-devel] vTPM Manager shuts down-----Original Message----- From: xen-devel-bounces@xxxxxxxxxxxxx [mailto:xen-devel- bounces@xxxxxxxxxxxxx] On Behalf Of Konrad Rzeszutek Wilk Sent: Wednesday, May 22, 2013 2:00 PM To: Daniel De Graaf Cc: Jordi Cucurull Juan; xen-devel@xxxxxxxxxxxxx Subject: Re: [Xen-devel] vTPM Manager shuts down(XEN) General information for domain 5: (XEN) refcnt=3 dying=0 pause_count=0 (XEN) nr_pages=7168 xenheap_pages=5 shared_pages=0paged_pages=0 The ACPI firmware entry is meant to be present for ease of use in an OS that expects devices to have ACPI entries, not as the primary source of the address. In an environment using TBOOT, for example, this ACPI table may not be trusted to report the address correctly. As to your other question, I guess I never thought about whether there could or would be more than one actual TPM on a platform. I am not sure what that would be used for and it seems like the answer is "no" on the surface but I could be wrong. The TPM PC Client specification mandates that a TPM 1.2 be located at 0xFED40000 (in section 9.1 of the PC Client Specific TIS 1.21 or 5.2 in version 1.3, among other documents). This prevents multiple TPMs claiming to be a PC Client TPM. In general, having multiple TPMs on a single platform is not a useful configuration because it causes confusion when updating PCRs - which is a primary reason you would want your keys on TPM. Hm, I guess it wouldn't really work unless you added some new config option called 'vtpm_manager=1' to do this. The TPM manager already requires a command-line argument to change the locality (and therefore the address it uses to access the TPM), so it's not useful to try to auto-detect the address in one location while the other is still manual. -- Daniel De Graaf National Security Agency _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |