Received: by 2002:ac0:a5a7:0:0:0:0:0 with SMTP id m36-v6csp5771687imm; Mon, 23 Jul 2018 05:56:10 -0700 (PDT) X-Google-Smtp-Source: AAOMgpcAM8E23eCXaJs/oiCUK/rcTd5GUR5wUo4glNW2XFhCrT9OVXC13VGC2dKV0VxlLP8xOvR3 X-Received: by 2002:a63:2803:: with SMTP id o3-v6mr12297520pgo.158.1532350570344; Mon, 23 Jul 2018 05:56:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1532350570; cv=none; d=google.com; s=arc-20160816; b=iXfGijwqsB9p0a4D4t2kiYP+tcRkBtr2dSDX17oh2sE3AWGJxcUnfAi7NltpvxEBo0 MZuc7ne++gn2A/Jq7YPwuiVkGJVJvY9qohHcwvBNcvOb1/o2kGYVm+J/gRCXk3DtyupZ B3JBwzcjROvDfaSevK5j6CQDFIyLfvI99eaIex/ZKYuBme2R6/lZW+7Ih5Og9nHDi7M1 xQWuWnr3MqYFZmdxXiBbB8HOhiG9O4iVt8ATtV2TWh08k+M0BrwK2kjthBUEoCNR84Rq NdWIVhl9pN/qpn6xB0qukf7UjWiXjjiEAKENgbM9KoYFDDsuONAOnTrMZp+Opo32Vw53 EASA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :organization:references:in-reply-to:date:cc:to:from:subject :message-id:arc-authentication-results; bh=8t2v5BYHML/fdcvMdXqzbZr18/M2GjImprjy2ilorHY=; b=onMW0uXPO7RLaWvciSNCecbrdxqpnkld0Fj+pE2VOfcXMicLHi7S0KV2vpvKU4r90x PUB+BwhlYKN8nFy8TBlK2HnjNO7EMLxNslUO/AN839KWb0hGloM7T6QD15m1XfRXPFaE +LC7p6kMSC6J8+OXU2+vAOZR4T3NpPMcmep3zl8xcm3p0ndf6/deQ9mqGCEoChFHgMvT 7f9xHBvU7qKkj2WLp9wGbmdOiq1U2GUrDOi6qzNW/1LkUA5qQP9eriGU1WQetZUAy/zh i9upJXwibEs4v0LUul1QiWcyAWopnOowa7icuwqzY3uF7KadvXmoZZg+bUrI1czHs90t v9BQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id f16-v6si8687426pff.13.2018.07.23.05.55.55; Mon, 23 Jul 2018 05:56:10 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2388435AbeGWNnx convert rfc822-to-8bit (ORCPT + 99 others); Mon, 23 Jul 2018 09:43:53 -0400 Received: from metis.ext.pengutronix.de ([85.220.165.71]:59189 "EHLO metis.ext.pengutronix.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2388306AbeGWNnv (ORCPT ); Mon, 23 Jul 2018 09:43:51 -0400 Received: from rettich.hi.pengutronix.de ([2001:67c:670:100:1d::c3] helo=rettich) by metis.ext.pengutronix.de with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1fhaAi-0006Hw-HC; Mon, 23 Jul 2018 14:42:40 +0200 Received: from jlu by rettich with local (Exim 4.89) (envelope-from ) id 1fhaAe-0007Gm-Sy; Mon, 23 Jul 2018 14:42:36 +0200 Message-ID: <1532349756.4604.85.camel@pengutronix.de> Subject: Re: [PATCH 1/2] security/keys/secure_key: Adds the secure key support based on CAAM. From: Jan =?ISO-8859-1?Q?L=FCbbe?= To: Udit Agarwal , "dhowells@redhat.com" , "zohar@linux.vnet.ibm.com" , "jmorris@namei.org" , "serge@hallyn.com" , "linux-integrity@vger.kernel.org" , "keyrings@vger.kernel.org" , "linux-security-module@vger.kernel.org" , "linux-kernel@vger.kernel.org" Cc: Sahil Malhotra , Ruchika Gupta , Horia Geanta , Aymen Sghaier Date: Mon, 23 Jul 2018 14:42:36 +0200 In-Reply-To: References: <20180720054656.29143-1-udit.agarwal@nxp.com> <1532076042.3511.203.camel@pengutronix.de> Organization: Pengutronix Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8BIT X-Mailer: Evolution 3.26.2-1 Mime-Version: 1.0 X-SA-Exim-Connect-IP: 2001:67c:670:100:1d::c3 X-SA-Exim-Mail-From: jlu@pengutronix.de X-SA-Exim-Scanned: No (on metis.ext.pengutronix.de); SAEximRunCond expanded to false X-PTX-Original-Recipient: linux-kernel@vger.kernel.org Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, On Sat, 2018-07-21 at 14:44 +0000, Udit Agarwal wrote: > Thanks for sharing the documentation changes and feedback. > > Below are the answers to the questions: > > 1. Currently the secure key patch series has been added to support > only data blobs. > It is not supporting key blobs as of now, we have thought of adding > that support in future. OK. Do have a plan how the key blobs would be represented in the keyring? It seems it would need to be some sort of handle instead of the key data. Would it need a different userspace API? > 2. Yes secure keys could also be implemented using OPTEE. I will > change the documentation in next patch version. Thanks! Jan