diff for duplicates of <20200528160527.GA27243@dell5510> diff --git a/a/1.txt b/N1/1.txt index 068524b..ad9f906 100644 --- a/a/1.txt +++ b/N1/1.txt @@ -1,6 +1,6 @@ Hi Mimi, ... -> > > With just this change, the ima_tpm.sh test is failing. I assume it is +> > > With just this change, the ima_tpm.sh test is failing. ?I assume it is > > > failing because it is reading the SHA1 TPM bank, not the SHA256 bank > > > to calculate the boot_aggregate hash. > > First question: is it correct to take sha256? Because on my test below it's @@ -13,7 +13,7 @@ Hi Mimi, > > What is needed to get your setup? > This isn't a configuration problem, but an issue of reading PCRs and -> calculating the TPM bank appropriate boot_aggregate. If you're +> calculating the TPM bank appropriate boot_aggregate. ?If you're > calculating a sha256 boot_aggregate, then the test needs to read and > calculate the boot_aggregate by reading the SHA256 TPM bank. OK, I tested it on TPM 1.2 (no TPM 2.0 available atm). @@ -37,8 +37,8 @@ So this patch would help at least testing on VM without vTPM. > > IMA I incline to just require evmctl. > Unlike TPM 1.2, the TPM 2.0 device driver doesn't export the TPM PCRs. -> Not only would you have a dependency on ima-evm-utils, but also on a -> userspace application(s) for reading the TPM PCRs. That dependency +> ?Not only would you have a dependency on ima-evm-utils, but also on a +> userspace application(s) for reading the TPM PCRs. ?That dependency > exists whether you're using evmctl to calculate the boot_aggregate or > doing it yourself. Hm, things get complicated. @@ -76,7 +76,7 @@ not sure if it indicate TPM 1.2, but I wouldn't rely on that. > [Cc'ing Vitaly] > The boot_aggregate.trs and boot_aggregate.log files are being created -> in the tests/ directory. Is that directory read-only? +> in the tests/ directory. ?Is that directory read-only? Yes, drwxr-xr-x. Testing on fresh clone and issue persists. > > > Both need some review and testing before being released. diff --git a/a/content_digest b/N1/content_digest index c323314..bd92efb 100644 --- a/a/content_digest +++ b/N1/content_digest @@ -3,20 +3,14 @@ "ref\020200528140747.GA8401@dell5510\0" "ref\01590679145.4457.39.camel@linux.ibm.com\0" "From\0Petr Vorel <pvorel@suse.cz>\0" - "Subject\0Re: [LTP v2 1/1] ima_tpm.sh: Fix for calculating boot aggregate\0" + "Subject\0[LTP] [LTP v2 1/1] ima_tpm.sh: Fix for calculating boot aggregate\0" "Date\0Thu, 28 May 2020 18:05:27 +0200\0" - "To\0Mimi Zohar <zohar@linux.ibm.com>\0" - "Cc\0ltp@lists.linux.it" - Mimi Zohar <zohar@linux.vnet.ibm.com> - Petr Cervinka <pcervinka@suse.com> - Cyril Hrubis <chrubis@suse.cz> - linux-integrity@vger.kernel.org - " Vitaly Chikunov <vt@altlinux.org>\0" + "To\0ltp@lists.linux.it\0" "\00:1\0" "b\0" "Hi Mimi,\n" "...\n" - "> > > With just this change, the ima_tpm.sh test is failing. \302\240I assume it is\n" + "> > > With just this change, the ima_tpm.sh test is failing. ?I assume it is\n" "> > > failing because it is reading the SHA1 TPM bank, not the SHA256 bank\n" "> > > to calculate the boot_aggregate hash.\n" "> > First question: is it correct to take sha256? Because on my test below it's\n" @@ -29,7 +23,7 @@ "> > What is needed to get your setup?\n" "\n" "> This isn't a configuration problem, but an issue of reading PCRs and\n" - "> calculating the TPM bank appropriate boot_aggregate. \302\240If you're\n" + "> calculating the TPM bank appropriate boot_aggregate. ?If you're\n" "> calculating a sha256 boot_aggregate, then the test needs to read and\n" "> calculate the boot_aggregate by reading the SHA256 TPM bank.\n" "OK, I tested it on TPM 1.2 (no TPM 2.0 available atm).\n" @@ -53,8 +47,8 @@ "> > IMA I incline to just require evmctl.\n" "\n" "> Unlike TPM 1.2, the TPM 2.0 device driver doesn't export the TPM PCRs.\n" - "> \302\240Not only would you have a dependency on ima-evm-utils, but also on a\n" - "> userspace application(s) for reading the TPM PCRs. \302\240That dependency\n" + "> ?Not only would you have a dependency on ima-evm-utils, but also on a\n" + "> userspace application(s) for reading the TPM PCRs. ?That dependency\n" "> exists whether you're using evmctl to calculate the boot_aggregate or\n" "> doing it yourself.\n" "Hm, things get complicated.\n" @@ -92,7 +86,7 @@ "> [Cc'ing Vitaly]\n" "\n" "> The boot_aggregate.trs and boot_aggregate.log files are being created\n" - "> in the tests/ directory. \302\240Is that directory read-only?\n" + "> in the tests/ directory. ?Is that directory read-only?\n" "Yes, drwxr-xr-x. Testing on fresh clone and issue persists.\n" "\n" "> > > Both need some review and testing before being released.\n" @@ -105,4 +99,4 @@ "Kind regards,\n" Petr -ffd1ce5658bf2942a5271c216745fd53cad87f6e6c3157acee7c89bb76b9e5e8 +00b5f75955cf64df53eeedef5f210eed3669c8e353b54eeaa8c10ffc0ff20de9
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.