Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1642771
| From | Ken Goldman <kgold@linux.vnet.ibm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() |
| Date | 2017-05-16 21:10 +0200 |
| Message-ID | <tHQ14-157-19@gated-at.bofh.it> (permalink) |
| References | <tHKf0-5Iw-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 5/16/2017 8:53 AM, Roberto Sassu wrote: > A new IMA measurement list format, called Crypto Agile, will be introduced > shortly to take full advantage of the algorithm flexibility of TPM 2.0. > With the new format, it will be possible to provide for each list entry > multiple digests, each calculated with an algorithm supported by the TPM. > Those digests will be used by remote entities to verify the integrity of > the measurements list. > > The current (SHA1) and the new (Crypto Agile) format definitions are: > > SHA1: pcr[4] digest[20] > template_name_len[4] template_name[template_name_len] > template_data_len[4] template_data[template_data_len] > > Crypto Agile: pcr[4] total_digest_len[4] > digest1_len[4] digest1[digest1_len] ... > digestN_len[4] digestN[digestN_len] > template_name_len[4] template_name[template_name_len] > template_data_len[4] template_data[template_data_len] 1 - In this proposed format, how does the parser or consumer of the log know what algorithm is used for digestN. For example, the TCG standard format uses TPML_DIGEST_VALUES uint32_t count - the number of digests TPMT_HA TPMT_HA digests[] where a TPMT_HA is algorithm identifier digest byte array 2 - Not a criticism, just a question for understanding ... Would it be true that the total_digest_length == the sum of all the digestN_len values plus 4 bytes for each length. Does it determine how many digests there are by when the total length is consumed?
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
[PATCH 4/7] ima: declare get_binary_runtime_size() as non-static Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
[PATCH 1/7] ima: introduce ima_parse_buf() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
[PATCH 7/7] ima: fix get_binary_runtime_size() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
[PATCH 6/7] ima: add securityfs interface to restore a measurements list Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
[PATCH 5/7] ima: add securityfs interface to save a measurements list with kexec header Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-16 21:10 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-17 09:30 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-17 18:30 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-18 11:40 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-23 22:50 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-24 10:30 +0200
Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-23 23:20 +0200
csiph-web