All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
To: "Fuchs, Andreas" <andreas.fuchs@sit.fraunhofer.de>
Cc: Peter Huewe <peterhuewe@gmx.de>,
	Marcel Selhorst <tpmdd@selhorst.net>,
	David Howells <dhowells@redhat.com>,
	Jonathan Corbet <corbet@lwn.net>,
	"open list:DOCUMENTATION" <linux-doc@vger.kernel.org>,
	open list <linux-kernel@vger.kernel.org>,
	"moderated list:TPM DEVICE DRIVER" 
	<tpmdd-devel@lists.sourceforge.net>,
	"open list:KEYS-ENCRYPTED"
	<linux-security-module@vger.kernel.org>,
	"open list:KEYS-ENCRYPTED" <keyrings@vger.kernel.org>,
	James Morris <james.l.morris@oracle.com>,
	"Serge E. Hallyn" <serge@hallyn.com>
Subject: Re: [tpmdd-devel] [PATCH 2/2] keys, trusted: seal with a policy
Date: Fri, 20 Nov 2015 16:53:08 +0200	[thread overview]
Message-ID: <20151120145308.GA31448@intel.com> (raw)
In-Reply-To: <9F48E1A823B03B4790B7E6E69430724D9D974334@EXCH2010B.sit.fraunhofer.de>

On Thu, Nov 19, 2015 at 10:59:57AM +0000, Fuchs, Andreas wrote:
> > ________________________________________
> > From: Jarkko Sakkinen [jarkko.sakkinen@linux.intel.com]
> > Sent: Tuesday, November 17, 2015 17:27
> > 
> > Support for sealing with a authorization policy.
> > 
> > Two new options for trusted keys:
> > 
> > * 'policydigest=': provide an auth policy digest for sealing.
> > * 'policyhandle=': provide a policy session handle for unsealing.
> 
> Hi Jarkko,
> 
> just out of curiosity; when testing this, how did you calculate the blobauth parameter ?
> Since its calculation requires the cpHash for the unseal()-command...
> If you "predict" the cpHash in userSpace, this would mean that userspace needs to know the
> kernels way of constructing the unseal()-command to the TPM, which in turn would make
> this part of the ABI and require documentation before upstreaming, imho.

Is this a comment about the patch? Have you actually read the source
code or where is this coming from? Please read the source code.

> Cheers,
> Andreas--

/Jarkko

  reply	other threads:[~2015-11-20 14:53 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-11-17 16:27 [PATCH 0/2] TPM 2.0 trusted key features for v4.5 Jarkko Sakkinen
2015-11-17 16:27 ` Jarkko Sakkinen
2015-11-17 16:27 ` [PATCH 1/2] keys, trusted: select hash algorithm for TPM2 chips Jarkko Sakkinen
2015-11-17 16:27   ` Jarkko Sakkinen
2015-11-17 16:27 ` [PATCH 2/2] keys, trusted: seal with a policy Jarkko Sakkinen
2015-11-18  0:21   ` James Morris
2015-11-18  7:03     ` Jarkko Sakkinen
2015-11-20  2:34       ` James Morris
2015-12-07  9:12         ` Jarkko Sakkinen
2015-12-07 22:35           ` James Morris
2015-12-08 11:01             ` Jarkko Sakkinen
2015-12-08 20:24               ` Jarkko Sakkinen
2015-12-08 23:56                 ` Mimi Zohar
2015-12-09 14:24                   ` Jarkko Sakkinen
2015-12-09 16:10                     ` Mimi Zohar
2015-11-19 10:59   ` [tpmdd-devel] " Fuchs, Andreas
2015-11-20 14:53     ` Jarkko Sakkinen [this message]
2015-11-21 18:50   ` Jarkko Sakkinen
2015-11-23 14:49   ` Jarkko Sakkinen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20151120145308.GA31448@intel.com \
    --to=jarkko.sakkinen@linux.intel.com \
    --cc=andreas.fuchs@sit.fraunhofer.de \
    --cc=corbet@lwn.net \
    --cc=dhowells@redhat.com \
    --cc=james.l.morris@oracle.com \
    --cc=keyrings@vger.kernel.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=peterhuewe@gmx.de \
    --cc=serge@hallyn.com \
    --cc=tpmdd-devel@lists.sourceforge.net \
    --cc=tpmdd@selhorst.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.