Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1642771

Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list()

From Ken Goldman <kgold@linux.vnet.ibm.com>
Newsgroups linux.kernel
Subject Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for ima_restore_measurement_list()
Date 2017-05-16 21:10 +0200
Message-ID <tHQ14-157-19@gated-at.bofh.it> (permalink)
References <tHKf0-5Iw-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 5/16/2017 8:53 AM, Roberto Sassu wrote:
> A new IMA measurement list format, called Crypto Agile, will be introduced
> shortly to take full advantage of the algorithm flexibility of TPM 2.0.
> With the new format, it will be possible to provide for each list entry
> multiple digests, each calculated with an algorithm supported by the TPM.
> Those digests will be used by remote entities to verify the integrity of
> the measurements list.
> 
> The current (SHA1) and the new (Crypto Agile) format definitions are:
> 
> SHA1: pcr[4] digest[20]
>        template_name_len[4] template_name[template_name_len]
>        template_data_len[4] template_data[template_data_len]
> 
> Crypto Agile: pcr[4] total_digest_len[4]
>                digest1_len[4] digest1[digest1_len] ...
>                digestN_len[4] digestN[digestN_len]
>                template_name_len[4] template_name[template_name_len]
>                template_data_len[4] template_data[template_data_len]

1 - In this proposed format, how does the parser or consumer of the log
know what algorithm is used for digestN.
For example, the TCG standard format uses TPML_DIGEST_VALUES
	uint32_t count - the number of digests TPMT_HA
	TPMT_HA digests[]

where a TPMT_HA is
	algorithm identifier
	digest byte array

2 - Not a criticism, just a question for understanding ...  Would it be 
true that the total_digest_length == the sum of all the digestN_len 
values plus 4 bytes for each length.

Does it determine how many digests there are by when the total length is 
consumed?

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/7] IMA: new parser for ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  [PATCH 4/7] ima: declare get_binary_runtime_size() as non-static Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  [PATCH 1/7] ima: introduce ima_parse_buf() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  [PATCH 7/7] ima: fix get_binary_runtime_size() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  [PATCH 6/7] ima: add securityfs interface to restore a measurements list Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  [PATCH 5/7] ima: add securityfs interface to save a measurements list with kexec header Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-16 15:00 +0200
  Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-16 21:10 +0200
    Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-17 09:30 +0200
      Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-17 18:30 +0200
        Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-18 11:40 +0200
          Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-23 22:50 +0200
            Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Roberto Sassu <roberto.sassu@huawei.com> - 2017-05-24 10:30 +0200
          Re: [Linux-ima-devel] [PATCH 0/7] IMA: new parser for  ima_restore_measurement_list() Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-05-23 23:20 +0200

csiph-web