[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20151120145308.GA31448@intel.com>
Date: Fri, 20 Nov 2015 16:53:08 +0200
From: Jarkko Sakkinen <jarkko.sakkinen@...ux.intel.com>
To: "Fuchs, Andreas" <andreas.fuchs@....fraunhofer.de>
Cc: Peter Huewe <peterhuewe@....de>,
Marcel Selhorst <tpmdd@...horst.net>,
David Howells <dhowells@...hat.com>,
Jonathan Corbet <corbet@....net>,
"open list:DOCUMENTATION" <linux-doc@...r.kernel.org>,
open list <linux-kernel@...r.kernel.org>,
"moderated list:TPM DEVICE DRIVER"
<tpmdd-devel@...ts.sourceforge.net>,
"open list:KEYS-ENCRYPTED" <linux-security-module@...r.kernel.org>,
"open list:KEYS-ENCRYPTED" <keyrings@...r.kernel.org>,
James Morris <james.l.morris@...cle.com>,
"Serge E. Hallyn" <serge@...lyn.com>
Subject: Re: [tpmdd-devel] [PATCH 2/2] keys, trusted: seal with a policy
On Thu, Nov 19, 2015 at 10:59:57AM +0000, Fuchs, Andreas wrote:
> > ________________________________________
> > From: Jarkko Sakkinen [jarkko.sakkinen@...ux.intel.com]
> > Sent: Tuesday, November 17, 2015 17:27
> >
> > Support for sealing with a authorization policy.
> >
> > Two new options for trusted keys:
> >
> > * 'policydigest=': provide an auth policy digest for sealing.
> > * 'policyhandle=': provide a policy session handle for unsealing.
>
> Hi Jarkko,
>
> just out of curiosity; when testing this, how did you calculate the blobauth parameter ?
> Since its calculation requires the cpHash for the unseal()-command...
> If you "predict" the cpHash in userSpace, this would mean that userspace needs to know the
> kernels way of constructing the unseal()-command to the TPM, which in turn would make
> this part of the ABI and require documentation before upstreaming, imho.
Is this a comment about the patch? Have you actually read the source
code or where is this coming from? Please read the source code.
> Cheers,
> Andreas--
/Jarkko
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists