Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1579272

Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion

From Ken Goldman <kgold@linux.vnet.ibm.com>
Newsgroups linux.kernel
Subject Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion
Date 2017-02-12 21:30 +0100
Message-ID <ta8Wt-2nt-1@gated-at.bofh.it> (permalink)
References <t9hp7-2HH-1@gated-at.bofh.it> <t9nkS-6uq-25@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 2/10/2017 11:46 AM, James Bottomley wrote:
> On Fri, 2017-02-10 at 04:03 -0600, Dr. Greg Wettstein wrote:
>> On Feb 9, 11:24am, James Bottomley wrote:

>> quote: 810 milliseconds
>> verify signature: 635 milliseconds
> ...
>
> Part of the way of reducing the latency is not to use the TPM for
> things that don't require secrecy: container signature verification is
> one such because the container is signed with a private key to which
> ...

Agreed.  There are a few times one would verify a signature inside the 
TPM, but they're far from mainstream:

1 - Early in the boot cycle, when there's no crypto library.

2 - When the crypto library doesn't support the required algorithm.

3 - When a ticket is needed to prove to the TPM later that it verified
the signature.

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session exhaustion "Dr. Greg Wettstein" <greg@wind.enjellic.com> - 2017-02-10 12:20 +0100
  Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session  exhaustion James Bottomley <James.Bottomley@HansenPartnership.com> - 2017-02-10 18:40 +0100
    Re: [tpmdd-devel] [RFC] tpm2-space: add handling for global session  exhaustion Ken Goldman <kgold@linux.vnet.ibm.com> - 2017-02-12 21:30 +0100

csiph-web