All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mimi Zohar <zohar@linux.ibm.com>
To: "Singh, Jashandeep" <jashandeep.singh@hpe.com>,
	Roberto Sassu <roberto.sassu@huawei.com>,
	Dmitry Kasatkin <dmitry.kasatkin@gmail.com>
Cc: Eric Snowberg <eric.snowberg@oracle.com>,
	"linux-integrity@vger.kernel.org"
	<linux-integrity@vger.kernel.org>,
	"linux-security-module@vger.kernel.org"
	<linux-security-module@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	Jashandeep Singh <jdsw@juniper.net>
Subject: Re: [PATCH] ima: select the SHA384 PCR bank for the boot aggregate
Date: Wed, 26 Aug 2026 17:20:56 -0400	[thread overview]
Message-ID: <4ea0433a82c219d6efdb83ad0bf267045c91a374.camel@linux.ibm.com> (raw)
In-Reply-To: <20260826191051.219090-1-jashandeep.singh@hpe.com>

On Wed, 2026-08-26 at 19:11 +0000, Singh, Jashandeep wrote:
> From: Jashandeep Singh <jdsw@juniper.net>
> 
> ima_calc_boot_aggregate() selects a TPM PCR bank matching the
> configured IMA hash algorithm, otherwise falling back to the SHA256
> bank or the SHA1 bank.
> 
> A TPM 2.0 can be provisioned with only the SHA384 bank enabled, with no
> SHA256 or SHA1 bank. None of the above then matched, selection failed
> with
> 
>     ima: No suitable TPM algorithm for boot aggregate
> 
> and the boot aggregate digest was left as zeros, as for TPM bypass,
> making remote attestation impossible.
> 
> Accept the SHA384 bank as a fallback. The configured IMA hash algorithm
> is still matched first.

FYI, all enabled TPM banks are extended.  Refer to the functions
ima_pcr_extend() and tpm_pcr_extend().

The IMA measurement list contains file data hashes based on the IMA default hash
algorithm.  Similarly, the boot_aggregate hash is calculated using the IMA
default hash algorithm.

If you're seeing "ima: No suitable TPM algorithm for boot aggregate", it
probably means no TPM banks are configured.

Mimi
 

  reply	other threads:[~2026-08-26 21:21 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26 19:11 [PATCH] ima: select the SHA384 PCR bank for the boot aggregate Singh, Jashandeep
2026-08-26 21:20 ` Mimi Zohar [this message]
     [not found]   ` <PH7PR84MB16549E7A6AC842D358493B0F96AE2@PH7PR84MB1654.NAMPRD84.PROD.OUTLOOK.COM>
2026-08-26 23:14     ` Mimi Zohar
2026-08-27 13:17       ` Roberto Sassu
2026-08-27 14:46         ` Singh, Jashandeep
2026-08-27 14:56           ` Roberto Sassu
2026-08-27 15:49             ` Mimi Zohar
2026-08-27 20:03               ` Singh, Jashandeep

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4ea0433a82c219d6efdb83ad0bf267045c91a374.camel@linux.ibm.com \
    --to=zohar@linux.ibm.com \
    --cc=dmitry.kasatkin@gmail.com \
    --cc=eric.snowberg@oracle.com \
    --cc=jashandeep.singh@hpe.com \
    --cc=jdsw@juniper.net \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=roberto.sassu@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.