Linux Power Management development
 help / color / mirror / Atom feed
From: James Bottomley <James.Bottomley@HansenPartnership.com>
To: Matthew Garrett <matthewg@nvidia.com>, mjg59@srcf.ucam.org
Cc: keyrings@vger.kernel.org, linux-integrity@vger.kernel.org,
	 rafael@kernel.org, linux-pm@vger.kernel.org,
	linux-efi@vger.kernel.org
Subject: Re: [PATCH 05/17] tpm: Add a kernel attestation key and signed audit digest retrieval
Date: Thu, 08 Oct 2026 18:45:15 +0200	[thread overview]
Message-ID: <c5d1b69763362db8a681d00d3325dd673c4db08b.camel@HansenPartnership.com> (raw)
In-Reply-To: <20261008132532.1155166-6-matthewg@nvidia.com>

On Thu, 2026-10-08 at 06:20 -0700, Matthew Garrett wrote:
[...]
> +/**
> + * tpm2_create_kernel_ak() - create the kernel attestation key
> + * @chip:	the TPM chip
> + * @handle:	set to the transient handle of the AK on success
> + * @x:		if not NULL, filled with the X coordinate of the AK
> public key
> + * @y:		if not NULL, filled with the Y coordinate of the AK
> public key
> + *
> + * Creates the kernel AK as a primary key in the owner hierarchy
> using a
> + * fixed template, so the same key is returned on every call until
> the
> + * TPM is cleared.  The owner hierarchy must have an empty auth
> value.
> + * The caller must hold the chip's ops lock and is responsible for
> + * flushing @handle with tpm2_flush_context().
> + *
> + * Return:
> + * * 0		- OK
> + * * -errno	- A system error
> + * * TPM_RC	- A TPM error
> + */
> +int tpm2_create_kernel_ak(struct tpm_chip *chip, u32 *handle, u8 *x,
> u8 *y)

Oof, there's a lot of duplication in here.  Basically you're creating a
signing primary key (technically it's not an attestation key because
they're supposed to be non-primary; this isn't a criticism because the
only consumer is the machine owner who doesn't need to use privacy
preserving AKs because they know all about the TPM in their own
machine).  The primary generation routines that exist in tpm2-
sessions.c:tpm2_create_primary() et al. already does most of this.  The
only real current difference is that it creates an encryption key not a
signing key, but that could have an additional bool argument
(signing=true/encryption=false) rather than duplicating the entire
routine set.

Regards,

James

  reply	other threads:[~2026-10-08 16:45 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 13:20 [RFC] Make hibernation work with lockdown Matthew Garrett
2026-10-08 13:20 ` [PATCH 01/17] tpm: Define a kernel-owned TPM NV index that can't be modified by userland Matthew Garrett
2026-10-08 13:41   ` Matthew Garrett
2026-10-08 16:24     ` Jarkko Sakkinen
2026-10-08 16:23   ` Jarkko Sakkinen
2026-10-09  8:33     ` Matthew Garrett
2026-10-08 17:06   ` Ilias Apalodimas
2026-10-08 13:20 ` [PATCH 02/17] efi: Add a mechanism to modify TPM state depending on kernel security features Matthew Garrett
2026-10-08 16:38   ` Jarkko Sakkinen
2026-10-08 13:20 ` [PATCH 03/17] tpm: Allow tpm2_start_auth_session() to start an audit session Matthew Garrett
2026-10-08 13:20 ` [PATCH 04/17] tpm: Log commands executed in " Matthew Garrett
2026-10-08 13:20 ` [PATCH 05/17] tpm: Add a kernel attestation key and signed audit digest retrieval Matthew Garrett
2026-10-08 16:45   ` James Bottomley [this message]
2026-10-09  8:29     ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 06/17] tpm: Use TPM2_NV_ReadPublic to read NV index names Matthew Garrett
2026-10-08 13:20 ` [PATCH 07/17] tpm: Add in-kernel support for reading NV indices Matthew Garrett
2026-10-08 13:20 ` [PATCH 08/17] tpm: Add NV define, undefine and write helpers Matthew Garrett
2026-10-08 13:20 ` [PATCH 09/17] tpm: Provision the kernel NV index at registration Matthew Garrett
2026-10-08 13:20 ` [PATCH 10/17] tpm: Move the bounds-checked response reader to a header Matthew Garrett
2026-10-08 13:20 ` [PATCH 11/17] tpm: Add kernel signing key creation with audited provenance Matthew Garrett
2026-10-08 17:00   ` James Bottomley
2026-10-09  8:31     ` Matthew Garrett
2026-10-08 13:20 ` [PATCH 12/17] tpm: Add signing with the kernel signing key Matthew Garrett
2026-10-08 13:20 ` [PATCH 13/17] tpm: Add verification of kernel signing key provenance Matthew Garrett
2026-10-08 13:20 ` [PATCH 14/17] PM: hibernate: Add image digest and signature page infrastructure Matthew Garrett
2026-10-08 13:20 ` [PATCH 15/17] PM: hibernate: Sign and verify images with a kernel-generated TPM key Matthew Garrett
2026-10-08 13:20 ` [PATCH 16/17] PM: hibernate: Refuse to verify images with a virtual TPM Matthew Garrett
2026-10-08 13:20 ` [PATCH 17/17] PM: hibernate: Allow hibernation under lockdown with signed images Matthew Garrett
2026-10-08 16:53   ` Jarkko Sakkinen
2026-10-09  8:31     ` Matthew Garrett
2026-10-08 15:56 ` [RFC] Make hibernation work with lockdown Jarkko Sakkinen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c5d1b69763362db8a681d00d3325dd673c4db08b.camel@HansenPartnership.com \
    --to=james.bottomley@hansenpartnership.com \
    --cc=keyrings@vger.kernel.org \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=matthewg@nvidia.com \
    --cc=mjg59@srcf.ucam.org \
    --cc=rafael@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox