From: James Bottomley <James.Bottomley@HansenPartnership.com>
To: Matthew Garrett <matthewg@nvidia.com>, mjg59@srcf.ucam.org
Cc: keyrings@vger.kernel.org, linux-integrity@vger.kernel.org,
rafael@kernel.org, linux-pm@vger.kernel.org,
linux-efi@vger.kernel.org
Subject: Re: [PATCH 13/17] tpm: Add verification of kernel signing key provenance
Date: Sat, 10 Oct 2026 11:42:58 +0200 [thread overview]
Message-ID: <aeedde06c51910afe5231d9f359bb8767c01b5bd.camel@HansenPartnership.com> (raw)
In-Reply-To: <20261008132532.1155166-14-matthewg@nvidia.com>
On Thu, 2026-10-08 at 06:20 -0700, Matthew Garrett wrote:
> Add tpm2_kernel_key_verify(), which checks the provenance produced by
> tpm2_kernel_key_create() and returns the public key it shows the
> kernel created. It checks that:
>
> * The session audit attestation is signed by this TPM's kernel AK
>
> * Replaying the logged cpHash and rpHash pairs from a zero digest
> reproduces the attested session digest
>
> * Each logged rpHash matches the recorded response parameters, and
> the commands were PCR_Read, NV_Read, and CreateLoaded in that order
>
> * PCR 5 was read, and held the value it holds now
>
> * The read of the NV index returned the magic value
>
> * The key created has exactly the attributes of a kernel signing key.
>
> Since userspace cannot store the magic value in the kernel NV index,
> this shows that the key was created while the kernel was in control
> of the TPM.
This does strike me as very elaborate, especially the ephemeral key
bit; would you countenance a simplification? Since all you want is
proof that the hibernate image hash matches the one the creating kernel
made, you could simply create your kernel only NV index as a PCR and
measure the hash directly to that. Since user space is barred from
writing, all you need is an audit of the measurement going into the NV
register (indeed, it could be an ordinary NV index you simply write the
hash value to), coupled with a read of PCR 5. Then your audit log
directly verifies the hibernate image hash and you don't have to bother
with the ephemeral keys.
Regards,
James
next prev parent reply other threads:[~2026-10-10 9:43 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 13:20 [RFC] Make hibernation work with lockdown Matthew Garrett
2026-10-08 13:20 ` [PATCH 01/17] tpm: Define a kernel-owned TPM NV index that can't be modified by userland Matthew Garrett
2026-10-08 13:41 ` Matthew Garrett
2026-10-08 16:24 ` Jarkko Sakkinen
2026-10-08 16:23 ` Jarkko Sakkinen
2026-10-09 8:33 ` Matthew Garrett
2026-10-08 17:06 ` Ilias Apalodimas
2026-10-10 9:22 ` James Bottomley
2026-10-08 13:20 ` [PATCH 02/17] efi: Add a mechanism to modify TPM state depending on kernel security features Matthew Garrett
2026-10-08 16:38 ` Jarkko Sakkinen
2026-10-08 13:20 ` [PATCH 03/17] tpm: Allow tpm2_start_auth_session() to start an audit session Matthew Garrett
2026-10-08 13:20 ` [PATCH 04/17] tpm: Log commands executed in " Matthew Garrett
2026-10-08 13:20 ` [PATCH 05/17] tpm: Add a kernel attestation key and signed audit digest retrieval Matthew Garrett
2026-10-08 16:45 ` James Bottomley
2026-10-09 8:29 ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 06/17] tpm: Use TPM2_NV_ReadPublic to read NV index names Matthew Garrett
2026-10-08 13:20 ` [PATCH 07/17] tpm: Add in-kernel support for reading NV indices Matthew Garrett
2026-10-08 13:20 ` [PATCH 08/17] tpm: Add NV define, undefine and write helpers Matthew Garrett
2026-10-08 13:20 ` [PATCH 09/17] tpm: Provision the kernel NV index at registration Matthew Garrett
2026-10-08 13:20 ` [PATCH 10/17] tpm: Move the bounds-checked response reader to a header Matthew Garrett
2026-10-08 13:20 ` [PATCH 11/17] tpm: Add kernel signing key creation with audited provenance Matthew Garrett
2026-10-08 17:00 ` James Bottomley
2026-10-09 8:31 ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 12/17] tpm: Add signing with the kernel signing key Matthew Garrett
2026-10-08 13:20 ` [PATCH 13/17] tpm: Add verification of kernel signing key provenance Matthew Garrett
2026-10-10 9:34 ` James Bottomley
2026-10-10 9:42 ` James Bottomley [this message]
2026-10-08 13:20 ` [PATCH 14/17] PM: hibernate: Add image digest and signature page infrastructure Matthew Garrett
2026-10-08 13:20 ` [PATCH 15/17] PM: hibernate: Sign and verify images with a kernel-generated TPM key Matthew Garrett
2026-10-08 13:20 ` [PATCH 16/17] PM: hibernate: Refuse to verify images with a virtual TPM Matthew Garrett
2026-10-08 13:20 ` [PATCH 17/17] PM: hibernate: Allow hibernation under lockdown with signed images Matthew Garrett
2026-10-08 16:53 ` Jarkko Sakkinen
2026-10-09 8:31 ` Matthew Garrett
2026-10-08 15:56 ` [RFC] Make hibernation work with lockdown Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aeedde06c51910afe5231d9f359bb8767c01b5bd.camel@HansenPartnership.com \
--to=james.bottomley@hansenpartnership.com \
--cc=keyrings@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-pm@vger.kernel.org \
--cc=matthewg@nvidia.com \
--cc=mjg59@srcf.ucam.org \
--cc=rafael@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox