Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1579272
| From | Ken Goldman <kgold@linux.vnet.ibm.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion |
| Date | 2017-02-12 21:30 +0100 |
| Message-ID | <ta8Wt-2nt-1@gated-at.bofh.it> (permalink) |
| References | <t9hp7-2HH-1@gated-at.bofh.it> <t9nkS-6uq-25@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 2/10/2017 11:46 AM, James Bottomley wrote: > On Fri, 2017-02-10 at 04:03 -0600, Dr. Greg Wettstein wrote: >> On Feb 9, 11:24am, James Bottomley wrote: >> quote: 810 milliseconds >> verify signature: 635 milliseconds > ... > > Part of the way of reducing the latency is not to use the TPM for > things that don't require secrecy: container signature verification is > one such because the container is signed with a private key to which > ... Agreed. There are a few times one would verify a signature inside the TPM, but they're far from mainstream: 1 - Early in the boot cycle, when there's no crypto library. 2 - When the crypto library doesn't support the required algorithm. 3 - When a ticket is needed to prove to the TPM later that it verified the signature.
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion "Dr. Greg Wettstein" <greg@wind.enjellic.com> - 2017-02-10 12:20 +0100
Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-10 18:40 +0100
Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-12 21:30 +0100
csiph-web