diff options
author | Linus Torvalds <torvalds@linux-foundation.org> | 2020-06-30 12:17:21 -0700 |
---|---|---|
committer | Linus Torvalds <torvalds@linux-foundation.org> | 2020-06-30 12:17:21 -0700 |
commit | b13f40bc69a16e465d21e23ca5adf4bf26365815 (patch) | |
tree | 0c4594e40a12600129ff43575de282f9a4a64658 /lib/dump_stack.c | |
parent | 7c30b859a947535f2213277e827d7ac7dcff9c84 (diff) | |
parent | 20c59ce010f84300f6c655d32db2610d3433f85c (diff) |
Merge tag 'integrity-v5.8-fix-2' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity
Pull integrity updates from Mimi Zohar:
"Include PCRs 8 & 9 in per TPM 2.0 bank boot_aggregate calculation.
Prior to Linux 5.8 the SHA1 "boot_aggregate" value was padded with 0's
and extended into the other TPM 2.0 banks.
Included in the Linux 5.8 open window, TPM 2.0 PCR bank specific
"boot_aggregate" values (PCRs 0 - 7) are calculated and extended into the TPM banks.
Distro releases are now shipping grub2 with TPM support, which extend
PCRs 8 & 9. I'd like for PCRs 8 & 9 to be included in the new
"boot_aggregate" calculations.
For backwards compatibility, if the hash is SHA1, these new PCRs are
not included in the boot aggregate"
* tag 'integrity-v5.8-fix-2' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity:
ima: extend boot_aggregate with kernel measurements
Diffstat (limited to 'lib/dump_stack.c')
0 files changed, 0 insertions, 0 deletions