All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mimi Zohar <zohar@linux.ibm.com>
To: "Michael Niewöhner" <linux@mniewoehner.de>,
	"Jarkko Sakkinen" <jarkko.sakkinen@linux.intel.com>,
	"James Bottomley" <James.Bottomley@HansenPartnership.com>,
	peterhuewe@gmx.de, jgg@ziepe.ca, arnd@arndb.de,
	linux-integrity@vger.kernel.org,
	linux-kernel <linux-kernel@vger.kernel.org>,
	"Nayna Jain" <nayna@linux.ibm.com>,
	"Ken Goldman" <kgold@linux.ibm.com>
Subject: Re: tpm_tis TPM2.0 not detected on cold boot
Date: Tue, 01 Jan 2019 11:38:21 -0500	[thread overview]
Message-ID: <1546360701.4069.168.camel@linux.ibm.com> (raw)
In-Reply-To: <0902784697eea3fc522e21a89cdecb745f12c83c.camel@mniewoehner.de>

On Tue, 2019-01-01 at 17:15 +0100, Michael Niewöhner wrote:
> On Mon, 2018-12-31 at 16:17 -0500, Mimi Zohar wrote:
> > On Sun, 2018-12-30 at 14:22 +0100, Michael Niewöhner wrote:
> > 
> > > > difference is that on a cold boot, the TPM takes longer to initialize.
> > > 
> > > Well, as I said. Waiting for 10, 20 or even 60 seconds in the boot manager
> > > does
> > > not solve the problem. So the problem is NOT that the TPM takes longer to
> > > initialize. Even adding a delay of 20 seconds before TPM init does not solve
> > > that while that should be more than enough time.
> > 
> > The purpose of commenting out the TPM2 selftest was to minimize the
> > TPM initialization delay, so that the TPM is ready before IMA.  After
> > James' patch that wasn't needed anymore.
> > 
> > Looking back at this thread, I see you're using systemd-boot, not
> > grub2.  When you commented out the systemd-boot timeout, IMA found the
> > TPM.  The question is why isn't the TPM ready with the timeout before
> > IMA (like above)?  Has systemd-boot done the selftest?
> 
> I am not sure wether systemd-boot touches TPM at all but I get the same
> behaviour with syslinux-efi.

From looking at the source code, it depends on whether systemd was
compiled with ENABLE_TPM enabled(eg. src/boot/efi/boot.c,
src/boot/efi/measure.c, src/boot/efi/stub.c).

Mimi


  reply	other threads:[~2019-01-01 16:38 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-12-16 13:32 tpm_tis TPM2.0 not detected on cold boot Michael Niewöhner
2018-12-22 13:47 ` Michael Niewöhner
2018-12-22 22:53   ` Mimi Zohar
2018-12-23 11:55     ` Michael Niewöhner
2018-12-25 13:55       ` Michael Niewöhner
2018-12-30  3:33         ` Mimi Zohar
2018-12-30 13:22           ` Michael Niewöhner
2018-12-31 18:10             ` Ken Goldman
2018-12-31 21:17             ` Mimi Zohar
2019-01-01 16:15               ` Michael Niewöhner
2019-01-01 16:38                 ` Mimi Zohar [this message]
2019-01-01 16:47                   ` Michael Niewöhner
2018-12-31 17:56           ` Ken Goldman
2019-01-03 13:27       ` Jarkko Sakkinen
2019-01-03 13:38         ` Michael Niewöhner
2019-01-03 15:04           ` Jarkko Sakkinen
2019-01-03 15:47             ` Michael Niewöhner
2019-01-04 11:58               ` Michael Niewöhner
2019-01-04 15:28                 ` Michael Niewöhner
2019-01-04 18:26                   ` Michael Niewöhner
2019-01-10 17:28                   ` Jarkko Sakkinen
2019-01-10 18:03                     ` Michael Niewöhner
2019-01-10 17:19               ` Jarkko Sakkinen
2019-01-10 18:00                 ` Michael Niewöhner
2019-01-03 13:41 ` Jarkko Sakkinen
2019-01-03 13:55   ` Michael Niewöhner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1546360701.4069.168.camel@linux.ibm.com \
    --to=zohar@linux.ibm.com \
    --cc=James.Bottomley@HansenPartnership.com \
    --cc=arnd@arndb.de \
    --cc=jarkko.sakkinen@linux.intel.com \
    --cc=jgg@ziepe.ca \
    --cc=kgold@linux.ibm.com \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux@mniewoehner.de \
    --cc=nayna@linux.ibm.com \
    --cc=peterhuewe@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.