Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1530660

Re: [PATCH v5 3/3] tpm: add securityfs support for TPM 2.0 firmware event log

From Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
Newsgroups linux.kernel
Subject Re: [PATCH v5 3/3] tpm: add securityfs support for TPM 2.0 firmware event log
Date 2016-11-26 14:00 +0100
Message-ID <sHKKe-6IQ-5@gated-at.bofh.it> (permalink)
References <sGJwX-7LD-11@gated-at.bofh.it> <sGJwX-7LD-39@gated-at.bofh.it> <sH9AZ-8bP-3@gated-at.bofh.it> <sHuFr-4La-3@gated-at.bofh.it>
Organization Intel Finland Oy - BIC 0357606-4 - Westendinkatu 7, 02160 Espoo

Show all headers | View raw


On Fri, Nov 25, 2016 at 12:43:17PM -0700, Jason Gunthorpe wrote:
> On Thu, Nov 24, 2016 at 11:10:57PM +0200, Jarkko Sakkinen wrote:
> > On Wed, Nov 23, 2016 at 12:27:37PM -0500, Nayna Jain wrote:
> > > Unlike the device driver support for TPM 1.2, the TPM 2.0 does
> > > not support the securityfs pseudo files for displaying the
> > > firmware event log.
> > > 
> > > This patch enables support for providing the TPM 2.0 event log in
> > > binary form. TPM 2.0 event log supports a crypto agile format that
> > > records multiple digests, which is different from TPM 1.2. This
> > > patch enables the tpm_bios_log_setup for TPM 2.0  and adds the
> > > event log parser which understand the TPM 2.0 crypto agile format.
> > > 
> > > Signed-off-by: Nayna Jain <nayna@linux.vnet.ibm.com>
> > 
> > I don't want to say much about this before I've tested it. I wonder
> > what cheap hardware I could use to test this. Any advice is on this
> > from anyone is much appreciated.
> 
> If you found a small ARM system with TPM you could customize the uboot
> to build an event log and pass it in via DT.
> 
> Not sure how much work that would be, does uboot have tpm code
> already?

I have BeagleBoard Rev C (omap3530 arm board) and it has GPIOs but at
the moment I do not possess a spare dTPM module. I'll ask my employer
for one. It's quite old (2009), which is a good thing because of range
of support I would presume...

If I get the spare dTPM I can do I2C/SPI through GPIOs as long as I find
a way to inject stuff to DT. Hmm.. that said I've never done this
before. I guess you can ask I2C/SPI driver somehow to use GPIOs?

> Jason

/Jarkko

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Re: [PATCH v5 3/3] tpm: add securityfs support for TPM 2.0 firmware  event log Jason Gunthorpe <jgunthorpe@obsidianresearch.com> - 2016-11-25 20:50 +0100
  Re: [PATCH v5 3/3] tpm: add securityfs support for TPM 2.0 firmware  event log Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-11-26 14:00 +0100

csiph-web