Re: [PATCH 0/6] Measuring TPM update counter in IMA

2023-08-03 Thread Stefan Berger
On 8/3/23 18:36, Mimi Zohar wrote: On Thu, 2023-08-03 at 18:09 -0400, Stefan Berger wrote: I can remove the kexec example if it is causing confusion.> Please let me know. I am not convinced we need this series ... :-( Your kexec series prevents further logging and especially PCR extensions

Re: [PATCH 0/6] Measuring TPM update counter in IMA

2023-08-03 Thread Mimi Zohar
On Thu, 2023-08-03 at 18:09 -0400, Stefan Berger wrote: > > I can remove the kexec example if it is causing confusion.> Please let me > > know. > > I am not convinced we need this series ... :-( Your kexec series prevents > further logging and especially PCR extensions after the frozen measureme

Re: [PATCH 0/6] Measuring TPM update counter in IMA

2023-08-03 Thread Stefan Berger
On 8/3/23 17:30, Tushar Sugandhi wrote: Thanks Stefan for reviewing this series. Appreciate it. On 8/3/23 06:37, Stefan Berger wrote: On 8/1/23 14:19, Tushar Sugandhi wrote: Entries in IMA log may be lost due to code bugs, certain error conditions I hope we don't have such bugs. And I

Re: [PATCH 0/6] Measuring TPM update counter in IMA

2023-08-03 Thread Tushar Sugandhi
Thanks Stefan for reviewing this series. Appreciate it. Re-sending this email. I accidentally had some HTML content, the email bounced back from integrity mailing list. On 8/3/23 06:37, Stefan Berger wrote: On 8/1/23 14:19, Tushar Sugandhi wrote: Entries in IMA log may be lost due to code bug

Re: [PATCH 0/6] Measuring TPM update counter in IMA

2023-08-03 Thread Stefan Berger
On 8/1/23 14:19, Tushar Sugandhi wrote: Entries in IMA log may be lost due to code bugs, certain error conditions I hope we don't have such bugs. And I guess the most critical ones would be between logging and PCR extensions being met etc. This can result in TPM PCRs getting out of sync w

[PATCH 0/6] Measuring TPM update counter in IMA

2023-08-01 Thread Tushar Sugandhi
Entries in IMA log may be lost due to code bugs, certain error conditions being met etc. This can result in TPM PCRs getting out of sync with the IMA log. One such example is events between kexec 'load' and kexec 'execute' getting lost from the IMA log when the system soft-boots into the new Kern