[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [Xen-devel] [PATCH 0/2] vtpm deep quote in locality 0
Right now, deep quote functionality is enabled just when vtpm manager is started with locality=2. This requirement is enforced by the current implementation which uses PCRs that can be reset in locality 2: 20,21,22,23. Since some TPM chips do not enable access to other locality than 0 this patch enables the deep quote functionality for vtpm manager started with locality=0. The patches are based on a suggestion given by Daniel De Graaf in another thread on the list: - Add a field to the request - extraInfoFlags - Compute externData = SHA1 ( extraInfoFlags requestData [UUIDs if requested] [vTPM measurements if requested] [vTPM group update policy if requested] ) - Perform deep quotes using the above externData value instead of the value provided by the vTPM. Embedding additional data in externData is equivalently secure as extending it into PCRs. This change also has the benefit of increasing the flexibility of the request. It is simple to define additional flags and add data to the hash if needed. Emil Condrea (2): vtpm: deep quote flags vtpmmgr: execute deep quote in locality 0 stubdom/Makefile | 1 + stubdom/vtpm-deepquote-anyloc.patch | 127 ++++++++++++++++++++++++++++++++++++ stubdom/vtpm/vtpm_cmd.c | 13 ++-- stubdom/vtpmmgr/marshal.h | 1 + stubdom/vtpmmgr/mgmt_authority.c | 89 ++++++++++++++++++++++--- stubdom/vtpmmgr/mgmt_authority.h | 2 +- stubdom/vtpmmgr/vtpm_cmd_handler.c | 7 +- stubdom/vtpmmgr/vtpm_manager.h | 16 +++++ 8 files changed, 238 insertions(+), 18 deletions(-) create mode 100644 stubdom/vtpm-deepquote-anyloc.patch -- 2.1.0 _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |