linux-integrity.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* ima pcr question
@ 2020-01-14  0:06 Jerry Snitselaar
  2020-01-14  1:17 ` Mimi Zohar
  0 siblings, 1 reply; 8+ messages in thread
From: Jerry Snitselaar @ 2020-01-14  0:06 UTC (permalink / raw)
  To: Mimi Zohar, linux-integrity

We had a report of messages from ima saying "Error communicating with
TPM".  Looking into it a bit, it looks like with some Dell systems
(possibly others as well) in the bios they can set the hash algorithm
being used. In this case with that set to sha256 the messages
appear. Flipping the system to using sha1 makes them disappear.
Looking at the ima code, ima_calc_boot_aggregate_tfm hard codes using
sha1. Should that be changed to use whatever the default is in the
config, or possibly find out from the tpm what algorithm is being used?

Regards,
Jerry


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2020-01-20  0:13 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-01-14  0:06 ima pcr question Jerry Snitselaar
2020-01-14  1:17 ` Mimi Zohar
2020-01-17 22:29   ` Jerry Snitselaar
2020-01-17 23:00     ` James Bottomley
2020-01-18 19:14       ` Jerry Snitselaar
2020-01-18 23:20         ` Jerry Snitselaar
2020-01-18 23:51           ` James Bottomley
2020-01-20  0:13             ` Mimi Zohar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).