[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20171120224256.kz3qvz4ek6ky7ywc@pd.tnic>
Date: Mon, 20 Nov 2017 23:42:56 +0100
From: Borislav Petkov <bp@...en8.de>
To: Jarkko Sakkinen <jarkko.sakkinen@...ux.intel.com>
Cc: intel-sgx-kernel-dev@...ts.01.org,
platform-driver-x86@...r.kernel.org, linux-kernel@...r.kernel.org
Subject: Re: [PATCH v5 11/11] intel_sgx: driver documentation
On Tue, Nov 21, 2017 at 12:37:41AM +0200, Jarkko Sakkinen wrote:
> Firmware cannot access the memory inside an enclave. CPU asserts every
> memory access coming outside the enclave.
But "firmware could potentially configure the root key hash for the
enclave." How about the owner configures the root key hash instead?
Along with deciding whether to lock down the feature control register or
not...
--
Regards/Gruss,
Boris.
Good mailing practices for 400: avoid top-posting and trim the reply.
Powered by blists - more mailing lists