On Thu, 2020-06-18 at 16:11 -0400, Maurizio Drocco wrote:
> From: Maurizio <[email protected]>
> 
> If PCRs 8 - 9 are set (i.e. not all-zeros), cal_bootaggr should include
> them into the digest.
> 
> Signed-off-by: Maurizio Drocco <[email protected]>
> ---
>  src/evmctl.c | 16 +++++++++++++++-
>  1 file changed, 15 insertions(+), 1 deletion(-)
> 
> diff --git a/src/evmctl.c b/src/evmctl.c
> index 1d065ce..554571e 100644
> --- a/src/evmctl.c
> +++ b/src/evmctl.c
> @@ -1930,6 +1930,18 @@ static void calc_bootaggr(struct tpm_bank_info *bank)
>               }
>       }
>  
> +     if (strcmp(bank->algo_name, "sha1") != 0) {
> +             for (i = 8; i < 10; i++) {
> +                     if (memcmp(bank->pcr[i], zero, bank->digest_size) != 0) 
> {
> +                             err = EVP_DigestUpdate(pctx, bank->pcr[i], 
> bank->digest_size);
> +                             if (!err) {
> +                                     log_err("EVP_DigestUpdate() failed\n");
> +                                     return;
> +                             }
> +                     }
> +             }
> +     }

Roberto, now that we're only including the PCRs 8 & 9 in the non-sha1
"boot_aggregate", they can always be included.

Please reflect this change in the patch description and, here, in the
code.

thanks,

Mimi

Reply via email to