All of lore.kernel.org
 help / color / mirror / Atom feed
* ima-evm-utils: version 1.4 released
@ 2021-11-04 23:10 Mimi Zohar
  2021-11-05  8:15 ` Petr Vorel
  0 siblings, 1 reply; 13+ messages in thread
From: Mimi Zohar @ 2021-11-04 23:10 UTC (permalink / raw)
  To: linux-integrity; +Cc: Petr Vorel, Vitaly Chikunov, Bruno E. O. Meneguele

Please refer to the NEWS file for the short summary and the git history
for details of the ima-evm-utils v1.4 release.

thanks,

Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-04 23:10 ima-evm-utils: version 1.4 released Mimi Zohar
@ 2021-11-05  8:15 ` Petr Vorel
  2021-11-05 16:21   ` Lakshmi Ramasubramanian
  0 siblings, 1 reply; 13+ messages in thread
From: Petr Vorel @ 2021-11-05  8:15 UTC (permalink / raw)
  To: Mimi Zohar; +Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

Hi Mimi,

> Please refer to the NEWS file for the short summary and the git history
> for details of the ima-evm-utils v1.4 release.
Thanks for info, congrats!
Going to update openSUSE.

Kind regards,
Petr

> thanks,

> Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-05  8:15 ` Petr Vorel
@ 2021-11-05 16:21   ` Lakshmi Ramasubramanian
  2021-11-05 17:28     ` Mimi Zohar
                       ` (2 more replies)
  0 siblings, 3 replies; 13+ messages in thread
From: Lakshmi Ramasubramanian @ 2021-11-05 16:21 UTC (permalink / raw)
  To: Petr Vorel, Mimi Zohar
  Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele


On 11/5/2021 1:15 AM, Petr Vorel wrote:
> Hi Mimi,
> 
>> Please refer to the NEWS file for the short summary and the git history
>> for details of the ima-evm-utils v1.4 release.

Thanks for the info Mimi.

I checked both "master" and "next-testing" branches in the following, 
and I still see 1.3.2 version only.

	https://github.com/pevik/ima-evm-utils

Is there a different github url for the latest ima-evm-utils source?

I am seeing the following errors when trying to validate IMA measurement 
using the util. I'd like to try the latest (v1.4).

sudo ./evmctl ima_measurement
/sys/kernel/security/ima/binary_runtime_measurements  -vv

Error messages for the above command
------------------------------------
Using tsspcrread to read PCRs.

tpm2_pcr_supported:67 Found 'tsspcrread' in $PATHread_tpm_banks:1923
Failed to read sha1 PCRs: (TSS_Socket_Open: Error on connect to
localhost:2321)

read_tpm_banks:1923 Failed to read sha256 PCRs: (TSS_Socket_Open: Error
on connect to localhost:2321)

Failed to read any TPM PCRs

thanks,
  -lakshmi



^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-05 16:21   ` Lakshmi Ramasubramanian
@ 2021-11-05 17:28     ` Mimi Zohar
  2021-11-08 20:40       ` Petr Vorel
  2021-11-07 22:02     ` Petr Vorel
  2021-11-08 19:46     ` Ken Goldman
  2 siblings, 1 reply; 13+ messages in thread
From: Mimi Zohar @ 2021-11-05 17:28 UTC (permalink / raw)
  To: Lakshmi Ramasubramanian, Petr Vorel
  Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

On Fri, 2021-11-05 at 09:21 -0700, Lakshmi Ramasubramanian wrote:
> On 11/5/2021 1:15 AM, Petr Vorel wrote:
> > Hi Mimi,
> > 
> >> Please refer to the NEWS file for the short summary and the git history
> >> for details of the ima-evm-utils v1.4 release.
> 
> Thanks for the info Mimi.
> 
> I checked both "master" and "next-testing" branches in the following, 
> and I still see 1.3.2 version only.
> 
> 	https://github.com/pevik/ima-evm-utils
> 
> Is there a different github url for the latest ima-evm-utils source?

The original sf git repo https://sourceforge.net/projects/linux-ima/
and the new github https://github.com/mimizohar/ima-evm-utils.

Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-05 16:21   ` Lakshmi Ramasubramanian
  2021-11-05 17:28     ` Mimi Zohar
@ 2021-11-07 22:02     ` Petr Vorel
  2021-11-08 19:46     ` Ken Goldman
  2 siblings, 0 replies; 13+ messages in thread
From: Petr Vorel @ 2021-11-07 22:02 UTC (permalink / raw)
  To: Lakshmi Ramasubramanian
  Cc: Mimi Zohar, linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

Hi Lakshmi, all,

> On 11/5/2021 1:15 AM, Petr Vorel wrote:
> > Hi Mimi,

> > > Please refer to the NEWS file for the short summary and the git history
> > > for details of the ima-evm-utils v1.4 release.

> Thanks for the info Mimi.

> I checked both "master" and "next-testing" branches in the following, and I
> still see 1.3.2 version only.

> 	https://github.com/pevik/ima-evm-utils
FYI this is my unofficial fork which I used for Travis testing, now used for
GitHub actions testing. I stated it's unofficial since it's creation in About
section.

Kind regards,
Petr

> Is there a different github url for the latest ima-evm-utils source?

> I am seeing the following errors when trying to validate IMA measurement
> using the util. I'd like to try the latest (v1.4).

> sudo ./evmctl ima_measurement
> /sys/kernel/security/ima/binary_runtime_measurements  -vv

> Error messages for the above command
> ------------------------------------
> Using tsspcrread to read PCRs.

> tpm2_pcr_supported:67 Found 'tsspcrread' in $PATHread_tpm_banks:1923
> Failed to read sha1 PCRs: (TSS_Socket_Open: Error on connect to
> localhost:2321)

> read_tpm_banks:1923 Failed to read sha256 PCRs: (TSS_Socket_Open: Error
> on connect to localhost:2321)

> Failed to read any TPM PCRs

> thanks,
>  -lakshmi



^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-05 16:21   ` Lakshmi Ramasubramanian
  2021-11-05 17:28     ` Mimi Zohar
  2021-11-07 22:02     ` Petr Vorel
@ 2021-11-08 19:46     ` Ken Goldman
  2021-11-08 20:46       ` Lakshmi Ramasubramanian
  2 siblings, 1 reply; 13+ messages in thread
From: Ken Goldman @ 2021-11-08 19:46 UTC (permalink / raw)
  To: Lakshmi Ramasubramanian, Petr Vorel, Mimi Zohar
  Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

[-- Attachment #1: Type: text/plain, Size: 1256 bytes --]

On 11/5/2021 12:21 PM, Lakshmi Ramasubramanian wrote:
> 
> On 11/5/2021 1:15 AM, Petr Vorel wrote:
>> Hi Mimi,
>>
>>> Please refer to the NEWS file for the short summary and the git history
>>> for details of the ima-evm-utils v1.4 release.
> 
> Thanks for the info Mimi.
> 
> I checked both "master" and "next-testing" branches in the following, and I still see 1.3.2 version only.
> 
>      https://github.com/pevik/ima-evm-utils
> 
> Is there a different github url for the latest ima-evm-utils source?
> 
> I am seeing the following errors when trying to validate IMA measurement using the util. I'd like to try the latest (v1.4).
> 
> sudo ./evmctl ima_measurement
> /sys/kernel/security/ima/binary_runtime_measurements  -vv
> 
> Error messages for the above command
> ------------------------------------
> Using tsspcrread to read PCRs.
> 
> tpm2_pcr_supported:67 Found 'tsspcrread' in $PATHread_tpm_banks:1923
> Failed to read sha1 PCRs: (TSS_Socket_Open: Error on connect to
> localhost:2321)
> 
> read_tpm_banks:1923 Failed to read sha256 PCRs: (TSS_Socket_Open: Error
> on connect to localhost:2321)
> 
> Failed to read any TPM PCRs
>

This sounds like your program is trying to connect to a SW TPM,
and the SW TPM process is not running.


[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 4490 bytes --]

^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-05 17:28     ` Mimi Zohar
@ 2021-11-08 20:40       ` Petr Vorel
  2021-11-09  2:17         ` Mimi Zohar
  0 siblings, 1 reply; 13+ messages in thread
From: Petr Vorel @ 2021-11-08 20:40 UTC (permalink / raw)
  To: Mimi Zohar
  Cc: Lakshmi Ramasubramanian, linux-integrity, Vitaly Chikunov,
	Bruno E. O. Meneguele

Hi Mimi,

> On Fri, 2021-11-05 at 09:21 -0700, Lakshmi Ramasubramanian wrote:
> > On 11/5/2021 1:15 AM, Petr Vorel wrote:
> > > Hi Mimi,

> > >> Please refer to the NEWS file for the short summary and the git history
> > >> for details of the ima-evm-utils v1.4 release.

> > Thanks for the info Mimi.

> > I checked both "master" and "next-testing" branches in the following, 
> > and I still see 1.3.2 version only.

> > 	https://github.com/pevik/ima-evm-utils

> > Is there a different github url for the latest ima-evm-utils source?

> The original sf git repo https://sourceforge.net/projects/linux-ima/
> and the new github https://github.com/mimizohar/ima-evm-utils.

Github repository is marked as primary. How about moving releases also to
GitHub?

Kind regards,
Petr

> Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-08 19:46     ` Ken Goldman
@ 2021-11-08 20:46       ` Lakshmi Ramasubramanian
  2021-11-08 22:24         ` Mimi Zohar
  0 siblings, 1 reply; 13+ messages in thread
From: Lakshmi Ramasubramanian @ 2021-11-08 20:46 UTC (permalink / raw)
  To: Ken Goldman, Petr Vorel, Mimi Zohar
  Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

Thanks for the response Ken.

>> I am seeing the following errors when trying to validate IMA 
>> measurement using the util. I'd like to try the latest (v1.4).
>>
>> sudo ./evmctl ima_measurement
>> /sys/kernel/security/ima/binary_runtime_measurements  -vv
>>
>> Error messages for the above command
>> ------------------------------------
>> Using tsspcrread to read PCRs.
>>
>> tpm2_pcr_supported:67 Found 'tsspcrread' in $PATHread_tpm_banks:1923
>> Failed to read sha1 PCRs: (TSS_Socket_Open: Error on connect to
>> localhost:2321)
>>
>> read_tpm_banks:1923 Failed to read sha256 PCRs: (TSS_Socket_Open: Error
>> on connect to localhost:2321)
>>
>> Failed to read any TPM PCRs
>>
> 
> This sounds like your program is trying to connect to a SW TPM,
> and the SW TPM process is not running.
> 

There is a physical TPM on the machine where I am running ima-evm-utils 
to verify IMA measurements. I want to use that physical TPM and not a 
software TPM.

I am seeing the error with v1.4 sources as well.

I will review ima-evm-utils code and check how to get it to use the 
physical TPM for validating the IMA measurements.

  -lakshmi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-08 20:46       ` Lakshmi Ramasubramanian
@ 2021-11-08 22:24         ` Mimi Zohar
  0 siblings, 0 replies; 13+ messages in thread
From: Mimi Zohar @ 2021-11-08 22:24 UTC (permalink / raw)
  To: Lakshmi Ramasubramanian, Ken Goldman, Petr Vorel
  Cc: linux-integrity, Vitaly Chikunov, Bruno E. O. Meneguele

On Mon, 2021-11-08 at 12:46 -0800, Lakshmi Ramasubramanian wrote:
> Thanks for the response Ken.
> 
> >> I am seeing the following errors when trying to validate IMA 
> >> measurement using the util. I'd like to try the latest (v1.4).
> >>
> >> sudo ./evmctl ima_measurement
> >> /sys/kernel/security/ima/binary_runtime_measurements  -vv
> >>
> >> Error messages for the above command
> >> ------------------------------------
> >> Using tsspcrread to read PCRs.
> >>
> >> tpm2_pcr_supported:67 Found 'tsspcrread' in $PATHread_tpm_banks:1923
> >> Failed to read sha1 PCRs: (TSS_Socket_Open: Error on connect to
> >> localhost:2321)
> >>
> >> read_tpm_banks:1923 Failed to read sha256 PCRs: (TSS_Socket_Open: Error
> >> on connect to localhost:2321)
> >>
> >> Failed to read any TPM PCRs
> >>
> > 
> > This sounds like your program is trying to connect to a SW TPM,
> > and the SW TPM process is not running.
> > 
> 
> There is a physical TPM on the machine where I am running ima-evm-utils 
> to verify IMA measurements. I want to use that physical TPM and not a 
> software TPM.
> 
> I am seeing the error with v1.4 sources as well.
> 
> I will review ima-evm-utils code and check how to get it to use the 
> physical TPM for validating the IMA measurements.

This release has support for linking with "-libmtss", in addition to
calling the command line tools.  Check the configure output to see
which TSS you're using.

If you're using the IBM TSS, first make sure that "tsspcrread -halg
sha256 -ha 10 -ns", for example, is actually working.

thanks,

Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-08 20:40       ` Petr Vorel
@ 2021-11-09  2:17         ` Mimi Zohar
  2021-11-16  9:45           ` Petr Vorel
  0 siblings, 1 reply; 13+ messages in thread
From: Mimi Zohar @ 2021-11-09  2:17 UTC (permalink / raw)
  To: Petr Vorel
  Cc: Lakshmi Ramasubramanian, linux-integrity, Vitaly Chikunov,
	Bruno E. O. Meneguele

Hi Petr,

On Mon, 2021-11-08 at 21:40 +0100, Petr Vorel wrote:
> Github repository is marked as primary. How about moving releases also to
> GitHub?

Done.

thanks,

Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-09  2:17         ` Mimi Zohar
@ 2021-11-16  9:45           ` Petr Vorel
  2021-11-24 18:57             ` Mimi Zohar
  0 siblings, 1 reply; 13+ messages in thread
From: Petr Vorel @ 2021-11-16  9:45 UTC (permalink / raw)
  To: Mimi Zohar
  Cc: Lakshmi Ramasubramanian, linux-integrity, Vitaly Chikunov,
	Bruno E. O. Meneguele

Hi Mimi,

> Hi Petr,

> On Mon, 2021-11-08 at 21:40 +0100, Petr Vorel wrote:
> > Github repository is marked as primary. How about moving releases also to
> > GitHub?

> Done.
Great, thank you! Also, when you have time, could you please put there
checksums? (ideally sha256/sha512) or even signed checksum file).

Kind regards,
Petr

> thanks,

> Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-16  9:45           ` Petr Vorel
@ 2021-11-24 18:57             ` Mimi Zohar
  2021-11-29 11:55               ` Petr Vorel
  0 siblings, 1 reply; 13+ messages in thread
From: Mimi Zohar @ 2021-11-24 18:57 UTC (permalink / raw)
  To: Petr Vorel
  Cc: Lakshmi Ramasubramanian, linux-integrity, Vitaly Chikunov,
	Bruno E. O. Meneguele

Hi Petr,

On Tue, 2021-11-16 at 10:45 +0100, Petr Vorel wrote:
> Hi Mimi,
> 
> Great, thank you! Also, when you have time, could you please put there
> checksums? (ideally sha256/sha512) or even signed checksum file).

The github documentation is lacking as to where to put the release
checksums or signed checksum file.  All I've found is that it isn't
supported.  Here are the hashes:

sha256:fcf85b31d6292051b3679e5f17ffa7f89b6898957aad0f59aa4e9878884b27d1
 
sha512:2fdf41470d88608162a084c4877ba17d531941b744bcb44dd4913e48ab2c2d13
1e0af3e3ead74c18748a5d46aced51213ebd7c13a5ee19050c28d54a26c011a3

thanks,

Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

* Re: ima-evm-utils: version 1.4 released
  2021-11-24 18:57             ` Mimi Zohar
@ 2021-11-29 11:55               ` Petr Vorel
  0 siblings, 0 replies; 13+ messages in thread
From: Petr Vorel @ 2021-11-29 11:55 UTC (permalink / raw)
  To: Mimi Zohar
  Cc: Lakshmi Ramasubramanian, linux-integrity, Vitaly Chikunov,
	Bruno E. O. Meneguele

Hi Mimi,

> Hi Petr,

> On Tue, 2021-11-16 at 10:45 +0100, Petr Vorel wrote:
> > Hi Mimi,

> > Great, thank you! Also, when you have time, could you please put there
> > checksums? (ideally sha256/sha512) or even signed checksum file).

> The github documentation is lacking as to where to put the release
> checksums or signed checksum file.  All I've found is that it isn't
> supported.  Here are the hashes:

> sha256:fcf85b31d6292051b3679e5f17ffa7f89b6898957aad0f59aa4e9878884b27d1

> sha512:2fdf41470d88608162a084c4877ba17d531941b744bcb44dd4913e48ab2c2d13
> 1e0af3e3ead74c18748a5d46aced51213ebd7c13a5ee19050c28d54a26c011a3

You can just generate files and checksum and upload them to the release, like
Cyril does for LTP [1]. iputils just creates checksums file and upload it's sign
[2] (having also signed is obviously better).

Kind regards,
Petr

[1] https://github.com/linux-test-project/ltp/releases/tag/20210927
[2] https://github.com/iputils/iputils/releases/tag/20210722

> thanks,

> Mimi


^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2021-11-29 11:57 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-11-04 23:10 ima-evm-utils: version 1.4 released Mimi Zohar
2021-11-05  8:15 ` Petr Vorel
2021-11-05 16:21   ` Lakshmi Ramasubramanian
2021-11-05 17:28     ` Mimi Zohar
2021-11-08 20:40       ` Petr Vorel
2021-11-09  2:17         ` Mimi Zohar
2021-11-16  9:45           ` Petr Vorel
2021-11-24 18:57             ` Mimi Zohar
2021-11-29 11:55               ` Petr Vorel
2021-11-07 22:02     ` Petr Vorel
2021-11-08 19:46     ` Ken Goldman
2021-11-08 20:46       ` Lakshmi Ramasubramanian
2021-11-08 22:24         ` Mimi Zohar

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.