tpmdd-devel.lists.sourceforge.net archive mirror
 help / color / mirror / Atom feed
* [Question]: Question on the hash algorithm of evm and pcr_extend?
@ 2017-02-23  9:36 Likun (Hw)
       [not found] ` <806EF96D8ABD354A89C18BBED3F86165B8B0D2CC-DDyGIOodwTO05WiQPbXitQK1hpo4iccwjNknBlVQO8k@public.gmane.org>
  0 siblings, 1 reply; 2+ messages in thread
From: Likun (Hw) @ 2017-02-23  9:36 UTC (permalink / raw)
  To: linux-ima-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org,
	 (tpmdd-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org)


[-- Attachment #1.1: Type: text/plain, Size: 708 bytes --]

Hi,

*         Is there any plan to support other evm_hmac algorithms (like we done on  ima file data hash algorithm), the sha2 or other recent algorithms are more hardened than sha1 after all.



*         We have supported arbitrary hash algorithms for ima file data measurement  since commit e7a2ad7eb6f48ad80c70a22dd8167fb34b409466, but the ima template hash algorithm is still sha1 due to
the tpm1.2 pcr limitation.
But as we all know ,the tpm2 has supported sha2/sm3 and other algorithms , is there any approach to use TPM2.0 better ? For example , could we use sha2 as default digest algorithm, and when we meet tpm1.2, we truncate the digest from 32 to 20 bytes ?
Best Regards,
Li Kun



[-- Attachment #1.2: Type: text/html, Size: 6008 bytes --]

[-- Attachment #2: Type: text/plain, Size: 202 bytes --]

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot

[-- Attachment #3: Type: text/plain, Size: 192 bytes --]

_______________________________________________
tpmdd-devel mailing list
tpmdd-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/tpmdd-devel

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-02-23 15:54 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-02-23  9:36 [Question]: Question on the hash algorithm of evm and pcr_extend? Likun (Hw)
     [not found] ` <806EF96D8ABD354A89C18BBED3F86165B8B0D2CC-DDyGIOodwTO05WiQPbXitQK1hpo4iccwjNknBlVQO8k@public.gmane.org>
2017-02-23 15:54   ` [Linux-ima-devel] " Mimi Zohar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).