From: christophe.ricard <christophe.ricard@gmail.com>
To: u-boot@lists.denx.de
Subject: [U-Boot] [PATCH 03/25] tpm: Add Kconfig options for TPMs
Date: Tue, 11 Aug 2015 23:45:29 +0200 [thread overview]
Message-ID: <55CA6CF9.9070707@gmail.com> (raw)
In-Reply-To: <1439304497-10081-4-git-send-email-sjg@chromium.org>
Hi Simon,
On 11/08/2015 16:47, Simon Glass wrote:
> Add new Kconfig options for TPMs in preparation for moving boards to use
> Kconfig for TPM configuration.
>
> Signed-off-by: Simon Glass <sjg@chromium.org>
> ---
>
> common/Kconfig | 12 ++++++++++++
> drivers/tpm/Kconfig | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++
> lib/Kconfig | 10 ++++++++++
> 3 files changed, 74 insertions(+)
>
> diff --git a/common/Kconfig b/common/Kconfig
> index 40cd69e..05faae9 100644
> --- a/common/Kconfig
> +++ b/common/Kconfig
> @@ -618,4 +618,16 @@ config CMD_REGULATOR
>
> endmenu
>
> +menu "Security commands"
> +config CMD_TPM
> + bool "Enable the 'tpm' command"
> + depends on TPM
> + help
> + This provides a means to talk to a TPM from the command line. A wide
> + range of commands if provided - see 'tpm help' for details. The
> + command requires a suitable TPM on your board and the correct driver
> + must be enabled.
> +
> +endmenu
> +
> endmenu
> diff --git a/drivers/tpm/Kconfig b/drivers/tpm/Kconfig
> index f408b8a..993d2d7 100644
> --- a/drivers/tpm/Kconfig
> +++ b/drivers/tpm/Kconfig
> @@ -1,7 +1,59 @@
> config TPM_TIS_SANDBOX
> bool "Enable sandbox TPM driver"
> + depends on SANDBOX
> help
> This driver emulates a TPM, providing access to base functions
> such as reading and writing TPM private data. This is enough to
> support Chrome OS verified boot. Extend functionality is not
> implemented.
> +
> +config TPM_ATMEL_TWI
> + bool "Enable Atmel TWI TPM device driver"
> + depends on TPM
> + help
> + This driver supports an Atmel TPM device connected on the I2C bus.
> + The usual tpm operations and the 'tpm' command can be used to talk
> + to the device using the standard TPM Interface Specification (TIS)
> + protocol
> +
> +config TPM_TIS_I2C
> + bool "Enable support for Infineon SLB9635/45 TPMs on I2C"
> + depends on TPM && DM_I2C
> + help
> + This driver supports Infineon TPM devices connected on the I2C bus.
> + The usual tpm operations and the 'tpm' command can be used to talk
> + to the device using the standard TPM Interface Specification (TIS)
> + protocol
> +
> +config TPM_TIS_I2C_BURST_LIMITATION
> + bool "Enable I2C burst length limitation"
> + depends on TPM_TIS_I2C
> + help
> + Some broken TPMs have a limitation on the number of bytes they can
> + receive in one message. Enable this option to allow you to set this
> + option. The can allow a broken TPM to be used by splitting messages
> + into separate pieces.
> +
> +config TPM_TIS_I2C_BURST_LIMITATION_LEN
> + int "Length"
> + depends on TPM_TIS_I2C_BURST_LIMITATION
> + help
> + Use this to set the burst limitation length
> +
> +config TPM_TIS_LPC
> + bool "Enable support for Infineon SLB9635/45 TPMs on LPC"
> + depends on TPM && X86
> + help
> + This driver supports Infineon TPM devices connected on the I2C bus.
> + The usual tpm operations and the 'tpm' command can be used to talk
> + to the device using the standard TPM Interface Specification (TIS)
> + protocol
> +
> +config TPM_AUTH_SESSIONS
> + bool "Enable TPM authentication session support"
> + depends on TPM
> + help
> + Enable support for authorised (AUTH1) commands as specified in the
> + TCG Main Specification 1.2. OIAP-authorised versions of the commands
> + TPM_LoadKey2 and TPM_GetPubKey are provided. Both features are
> + available using the 'tpm' command, too.
Won't you put all TPM drivers in a "TPM support" menu showing "Device
Drivers" parent ?
> diff --git a/lib/Kconfig b/lib/Kconfig
> index 884218a..0673072 100644
> --- a/lib/Kconfig
> +++ b/lib/Kconfig
> @@ -54,6 +54,16 @@ source lib/dhry/Kconfig
>
> source lib/rsa/Kconfig
>
> +config TPM
> + bool "Trusted Platform Module (TPM) Support"
> + help
> + This enables support for TPMs which can be used to provide security
> + features for your board. The TPM can be connected via LPC or I2C
> + and a sandbox TPM is provided for testing purposes. Use the 'tpm'
> + command to interactive the TPM. Driver model support is provided
> + for the low-level TPM interface, but only one TPM is supported at
> + a time by the TPM library.
> +
> menu "Hashing Support"
>
> config SHA1
Best Regards
Christophe
next prev parent reply other threads:[~2015-08-11 21:45 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-11 14:47 [U-Boot] [PATCH 00/25] dm: Convert TPM drivers to driver model Simon Glass
2015-08-11 14:47 ` [U-Boot] [PATCH 01/25] tpm: Remove old pre-driver-model I2C code Simon Glass
2015-08-11 21:41 ` christophe.ricard
2015-08-13 1:30 ` Simon Glass
2015-08-11 14:47 ` [U-Boot] [PATCH 02/25] tpm: Drop two unused options Simon Glass
2015-08-11 21:44 ` christophe.ricard
2015-08-11 14:47 ` [U-Boot] [PATCH 03/25] tpm: Add Kconfig options for TPMs Simon Glass
2015-08-11 21:45 ` christophe.ricard [this message]
2015-08-13 1:30 ` Simon Glass
2015-08-11 14:47 ` [U-Boot] [PATCH 04/25] tpm: Convert board config TPM options to Kconfig Simon Glass
2015-08-11 21:45 ` christophe.ricard
2015-08-11 14:47 ` [U-Boot] [PATCH 05/25] tpm: Convert drivers to use SPDX Simon Glass
2015-08-11 21:41 ` christophe.ricard
2015-08-11 14:47 ` [U-Boot] [PATCH 06/25] tpm: Move the I2C TPM code into one file Simon Glass
2015-08-11 21:42 ` christophe.ricard
2015-08-13 1:30 ` Simon Glass
2015-08-13 20:26 ` Christophe Ricard
2015-08-11 14:47 ` [U-Boot] [PATCH 07/25] tpm: tpm_tis_i2c: Drop unnecessary methods Simon Glass
2015-08-11 21:47 ` christophe.ricard
2015-08-13 1:30 ` Simon Glass
2015-08-13 20:28 ` Christophe Ricard
2015-08-13 22:53 ` Simon Glass
2015-08-11 14:48 ` [U-Boot] [PATCH 08/25] tpm: tpm_tis_i2c: Drop struct tpm_vendor_specific Simon Glass
2015-08-11 21:47 ` christophe.ricard
2015-08-13 1:30 ` Simon Glass
2015-08-13 20:32 ` Christophe Ricard
2015-08-13 22:53 ` Simon Glass
2015-08-11 14:48 ` [U-Boot] [PATCH 09/25] tpm: tpm_tis_i2c: Merge struct tpm_dev into tpm_chip Simon Glass
2015-08-11 21:46 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 10/25] tpm: tpm_tis_i2c: Merge struct tpm " Simon Glass
2015-08-11 21:46 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 11/25] tpm: tpm_tis_i2c: Move definitions into the header file Simon Glass
2015-08-11 21:45 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 12/25] tpm: tpm_tis_i2c: Simplify init code Simon Glass
2015-08-11 21:45 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 13/25] tpm: tpm_tis_i2c: Use a consistent tpm_tis_i2c_ prefix Simon Glass
2015-08-11 21:44 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 14/25] tpm: tpm_tis_i2c: Tidy up delays Simon Glass
2015-08-11 21:44 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 15/25] dm: tpm: Add a uclass for Trusted Platform Modules Simon Glass
2015-08-11 21:44 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 16/25] dm: tpm: Convert the TPM command and library to driver model Simon Glass
2015-08-11 21:43 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 17/25] dm: i2c: Add a command to adjust the offset length Simon Glass
2015-08-11 14:48 ` [U-Boot] [PATCH 18/25] tpm: Report tpm errors on the command line Simon Glass
2015-08-11 21:43 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 19/25] dm: tpm: sandbox: Convert TPM driver to driver model Simon Glass
2015-08-11 21:42 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 20/25] tpm: Check that parse_byte_string() has data to parse Simon Glass
2015-08-11 21:42 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 21/25] exynos: x86: dts: Add tpm nodes to the device tree for Chrome OS devices Simon Glass
2015-08-11 14:48 ` [U-Boot] [PATCH 22/25] dm: tpm: Convert I2C driver to driver model Simon Glass
2015-08-11 21:41 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 23/25] dm: tpm: Convert LPC " Simon Glass
2015-08-11 21:41 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 24/25] tpm: Add a 'tpm info' command Simon Glass
2015-08-11 21:40 ` christophe.ricard
2015-08-11 14:48 ` [U-Boot] [PATCH 25/25] tegra: nyan: Enable TPM command and driver Simon Glass
2015-08-11 21:40 ` christophe.ricard
2015-08-11 21:50 ` [U-Boot] [PATCH 00/25] dm: Convert TPM drivers to driver model christophe.ricard
2015-08-13 1:30 ` Simon Glass
2015-08-13 20:22 ` Christophe Ricard
2015-08-13 22:52 ` Simon Glass
2015-08-20 21:39 ` Simon Glass
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55CA6CF9.9070707@gmail.com \
--to=christophe.ricard@gmail.com \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox