Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S261199AbVEXADQ (ORCPT ); Mon, 23 May 2005 20:03:16 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S261259AbVEXACb (ORCPT ); Mon, 23 May 2005 20:02:31 -0400 Received: from mx1.redhat.com ([66.187.233.31]:54239 "EHLO mx1.redhat.com") by vger.kernel.org with ESMTP id S261228AbVEWX7R (ORCPT ); Mon, 23 May 2005 19:59:17 -0400 Date: Mon, 23 May 2005 19:59:09 -0400 (EDT) From: James Morris X-X-Sender: jmorris@thoron.boston.redhat.com To: Reiner Sailer cc: Pavel Machek , , , , , , Subject: Re: [PATCH 2 of 4] ima: related Makefile compile order change and Readme In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1269 Lines: 40 On Mon, 23 May 2005, Reiner Sailer wrote: > > It seems to me that the mechanism is sound... it does what the docs > > says. Another questions is "is it usefull"? > > > > Pavel > > > > We implemented some exemplary IMA-applications. If you like, visit our > project page and check out the references: > http://www.research.ibm.com/secure_systems_department/projects/tcglinux/ > There you also find a complete measurement list and a response of a measured > system replying to an authorized remote measurement-list-request. How did you retrieve the TPM-aggregate? I'm still not sure why exporting just the kernel measurement values via proc is useful. Wouldn't you need to retrieve the measurement list atomically with the TPM-aggregate? In which case, we'd need an interface which takes a nonce and returns the kernel measurement list and the TPM-aggregate together. Is the source of your example IMA attestation application available? - James -- James Morris - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/