* Re: [PATCH v2 01/13] docs: Warn about incomplete vtpmmgr TPM 2.0 support
@ 2021-05-08 18:37 Rich Persaud
0 siblings, 0 replies; 2+ messages in thread
From: Rich Persaud @ 2021-05-08 18:37 UTC (permalink / raw)
To: Jason Andryuk; +Cc: xen-devel, Ian Jackson, Wei Liu, Andrew Cooper
[-- Attachment #1: Type: text/plain, Size: 1533 bytes --]
On May 6, 2021, at 10:00, Jason Andryuk <jandryuk@gmail.com> wrote:
> The vtpmmgr TPM 2.0 support is incomplete. Add a warning about that to
> the documentation so others don't have to work through discovering it is
> broken.
>
> Signed-off-by: Jason Andryuk <jandryuk@gmail.com>
> Acked-by: Andrew Cooper <andrew.cooper3@citrix.com>
> ---
> docs/man/xen-vtpmmgr.7.pod | 11 +++++++++++
> 1 file changed, 11 insertions(+)
>
> diff --git a/docs/man/xen-vtpmmgr.7.pod b/docs/man/xen-vtpmmgr.7.pod
> index af825a7ffe..875dcce508 100644
> --- a/docs/man/xen-vtpmmgr.7.pod
> +++ b/docs/man/xen-vtpmmgr.7.pod
> @@ -222,6 +222,17 @@ XSM label, not the kernel.
>
> =head1 Appendix B: vtpmmgr on TPM 2.0
>
> +=head2 WARNING: Incomplete - cannot persist data
> +
> +TPM 2.0 support for vTPM manager is incomplete. There is no support for
> +persisting an encryption key, so vTPM manager regenerates primary and secondary
> +key handles each boot.
> +
> +Also, the vTPM manger group command implementation hardcodes TPM 1.2 commands.
> +This means running manage-vtpmmgr.pl fails when the TPM 2.0 hardware rejects
> +the TPM 1.2 commands. vTPM manager with TPM 2.0 cannot create groups and
> +therefore cannot persist vTPM contents.
> +
> =head2 Manager disk image setup:
>
> The vTPM Manager requires a disk image to store its encrypted data. The image
> --
> 2.30.2
Should SUPPORT.md also be updated?
https://xenbits.xen.org/gitweb/?p=xen.git;a=blob;f=SUPPORT.md;hb=refs/heads/master
Rich
[-- Attachment #2: Type: text/html, Size: 2423 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH v2 01/13] docs: Warn about incomplete vtpmmgr TPM 2.0 support
2021-05-06 13:59 [PATCH v2 00/13] vtpmmgr: Some fixes - still incomplete Jason Andryuk
@ 2021-05-06 13:59 ` Jason Andryuk
0 siblings, 0 replies; 2+ messages in thread
From: Jason Andryuk @ 2021-05-06 13:59 UTC (permalink / raw)
To: xen-devel; +Cc: Jason Andryuk, Ian Jackson, Wei Liu, Andrew Cooper
The vtpmmgr TPM 2.0 support is incomplete. Add a warning about that to
the documentation so others don't have to work through discovering it is
broken.
Signed-off-by: Jason Andryuk <jandryuk@gmail.com>
Acked-by: Andrew Cooper <andrew.cooper3@citrix.com>
---
docs/man/xen-vtpmmgr.7.pod | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/docs/man/xen-vtpmmgr.7.pod b/docs/man/xen-vtpmmgr.7.pod
index af825a7ffe..875dcce508 100644
--- a/docs/man/xen-vtpmmgr.7.pod
+++ b/docs/man/xen-vtpmmgr.7.pod
@@ -222,6 +222,17 @@ XSM label, not the kernel.
=head1 Appendix B: vtpmmgr on TPM 2.0
+=head2 WARNING: Incomplete - cannot persist data
+
+TPM 2.0 support for vTPM manager is incomplete. There is no support for
+persisting an encryption key, so vTPM manager regenerates primary and secondary
+key handles each boot.
+
+Also, the vTPM manger group command implementation hardcodes TPM 1.2 commands.
+This means running manage-vtpmmgr.pl fails when the TPM 2.0 hardware rejects
+the TPM 1.2 commands. vTPM manager with TPM 2.0 cannot create groups and
+therefore cannot persist vTPM contents.
+
=head2 Manager disk image setup:
The vTPM Manager requires a disk image to store its encrypted data. The image
--
2.30.2
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2021-05-08 18:38 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-05-08 18:37 [PATCH v2 01/13] docs: Warn about incomplete vtpmmgr TPM 2.0 support Rich Persaud
-- strict thread matches above, loose matches on Subject: below --
2021-05-06 13:59 [PATCH v2 00/13] vtpmmgr: Some fixes - still incomplete Jason Andryuk
2021-05-06 13:59 ` [PATCH v2 01/13] docs: Warn about incomplete vtpmmgr TPM 2.0 support Jason Andryuk
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).