Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755442Ab0KHSU3 (ORCPT ); Mon, 8 Nov 2010 13:20:29 -0500 Received: from igw2.watson.ibm.com ([129.34.20.6]:43927 "EHLO igw2.watson.ibm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752481Ab0KHSU1 convert rfc822-to-8bit (ORCPT ); Mon, 8 Nov 2010 13:20:27 -0500 Subject: Re: [PATCH v1.2 3/4] keys: add new trusted key-type From: David Safford To: Jason Gunthorpe Cc: Mimi Zohar , linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, keyrings@linux-nfs.org, linux-crypto@vger.kernel.org, David Howells , James Morris , Rajiv Andrade , Mimi Zohar In-Reply-To: <20101108170937.GA31501@obsidianresearch.com> References: <1289230246-3856-1-git-send-email-zohar@linux.vnet.ibm.com> <1289230246-3856-4-git-send-email-zohar@linux.vnet.ibm.com> <20101108170937.GA31501@obsidianresearch.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8BIT Date: Mon, 08 Nov 2010 13:18:33 -0500 Message-ID: <1289240313.6060.10.camel@localhost.localdomain> Mime-Version: 1.0 X-Mailer: Evolution 2.32.0 (2.32.0-2.fc14) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 956 Lines: 23 On Mon, 2010-11-08 at 10:09 -0700, Jason Gunthorpe wrote: > On Mon, Nov 08, 2010 at 10:30:45AM -0500, Mimi Zohar wrote: > > > pcrlock=n extends the designated PCR 'n' with a random value, > > so that a key sealed to that PCR may not be unsealed > > again until after a reboot. > > Nice, but this seems very strange to me, since it has nothing to do > with the key and could be done easially in userspace? > > Jason This is strictly for convenience in initramfs, so that the trusted key can be loaded and locked in a single command, with no need for an additional application to extend a PCR. As the the TPM driver already has support for extend, it's a trivial addition. dave -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/