Re: [tboot-devel] Joanna Black Hat slides

2009-02-20 Thread Hal Finney
STM, which should add confidence that the TXT mode is secure. Hal Finney -- Open Source Business Conference (OSBC), March 24-25, 2009, San Francisco, CA -OSBC tackles the biggest issue in open source: Open Sourcing the Enterprise

Re: [tboot-devel] tboot

2009-06-23 Thread Hal Finney
truly trustworthy Trusted Computing technology? Rant off! Hal Finney -- ___ tboot-devel mailing list tboot-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/tboot-devel

[tboot-devel] Intel's P-MAPS research project

2009-07-12 Thread Hal Finney
I recently learned about Intel's P-MAPS research project which provides an alternative way of using TPM+TXT to provide attestations and sealing in the context of a standard OS. Here is a link to the Intel Research blog post: http://blogs.intel.com/research/2009/04/p-maps_an_on-demand_hardware-r.ph

Re: [tboot-devel] Intel's P-MAPS research project

2009-07-22 Thread Hal Finney
On Tue, Jul 21, 2009 at 6:20 AM, Lil Evil wrote: > There are many different projects with similar goals out there: > BitVisor(sourcecode available somewhere) or Daonity and of course flickr, > probably more that I am not aware of. > They all seem to target a particular use case and scenario. > > C

[tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-28 Thread Hal Finney
what this means. My log is attached, including the hang and the relaunch of tboot. This is version 20090330 of tboot. Thanks very much - Hal Finney tbootfail1.log Description: Binary data -- Let Crystal Reports handle

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-29 Thread Hal Finney
nks is wrong with DMAR. > You will have to build and run it on linux. > > Thanks > Ross > > -Original Message- > From: Hal Finney [mailto:hal.fin...@gmail.com] > Sent: Tuesday, July 28, 2009 7:33 PM > To: tboot-devel@lists.sourceforge.net > Subject: [tboot-dev

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-29 Thread Hal Finney
04 PM, Shane Wang wrote: > Hi Hal > > The error code means VTd is disabled. > Is your VT-d enabled in your new BIOS and grub.conf? > > Thanks. > Shane > > Hal Finney wrote: >> >> I haven't run tboot in a while, but I'm trying it on my HP dc7800 and &g

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-30 Thread Hal Finney
ease try to add "iommu=on" in the command > line (i.e. the end of "module /boot/vmlinuz-2.6.30 ..." > > PS: do you know which platform HP dc7800 is? *Field or *Dale? > Can you see VTd lsoc (Azalia) WA in BIOS or somewhere? > > Thanks. > Shane > > Hal Finney w

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-30 Thread Hal Finney
(Forgot to respond to this last part): > Can you see VTd lsoc (Azalia) WA in BIOS or somewhere? I'm afraid these terms mean nothing to me. Azalia is something about HD Audio? I don't know what that has to do with VT-d. Googling for lsoc with VT-d or with Intel finds nothing relevant. And WA could

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-30 Thread Hal Finney
ith > it). Hal attached the trace in an earlier reply. > > Thanks > Ross > > -Original Message- > From: Martin Thiim [mailto:mar...@thiim.net] > Sent: Thursday, July 30, 2009 4:07 PM > To: Hal Finney > Cc: tboot-devel@lists.sourceforge.net > Subject: Re: [tboot-dev

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-31 Thread Hal Finney
an experimental SINIT with additional debugging outputs or error codes if that would help. I'll also try reverting the BIOS version and see if that makes a difference. Thanks for all your help - Hal Finney Press any key to continue. Press any key to continue. Press any key

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-31 Thread Hal Finney
t;> http://download.intel.com/technology/computing/vptech/Intel(r)_VT_for_Direct_IO.pdf >> >> I currently don't have access to my VT-d system so I can't give you a >> table of what it looks like on my machine but perhaps others could. >> >> Best regards,

Re: [tboot-devel] GETSEC[SENTER] fail on HP dc7800

2009-07-31 Thread Hal Finney
IOS which works with SINIT but reveals nothing when there is a failure. Neither is a great alternative. Hal Finney -- Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report

[tboot-devel] tboot broke my laptop! (twice!)

2009-08-16 Thread Hal Finney
tops are turned into bricks by running tboot. Hal Finney -- Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report design, integration and deployment - and focus on w

Re: [tboot-devel] SINIT fails on Q45

2009-08-18 Thread Hal Finney
27;s probably any harm. I think you can still add NV areas, like if you want to define a policy someday as to which versions of tboot can load, etc. Maybe someone else can confirm that (A) locking the NV RAM is necessary for the SINIT to run; and (B) locking it won't cause any trouble with fut

Re: [tboot-devel] tboot broke my laptop! (twice!)

2009-08-18 Thread Hal Finney
that might be possible if I take the laptop apart somewhat? HP does have instructions to do so on the web site. Hal Finney On Mon, Aug 17, 2009 at 6:18 PM, Wang, Shane wrote: > Hi Hal, > > The reset behavior seems like it is due to the secret flag of TXT. > It looks like BIOS ACM doe

[tboot-devel] TXT attack by Invisible Things

2009-12-22 Thread Hal Finney
t we can query to see which SINITs are good and which are bad? Intel is going to be in trouble if anyone actually starts to use this technology, with their current lack of attention to these kinds of details! Hal Finney --

Re: [tboot-devel] Reading embedded EK's certs from a TPM?

2012-08-09 Thread Hal Finney
http://www.finney.org/~hal/privacyca/code.html#getcert is some code I wrote a few years ago to use Trousers to read the EK cert. Hal Finney -- Live Security Virtual Conference Exclusive live event will cover all the

Re: [tboot-devel] Reading embedded EK's certs from a TPM?

2012-08-12 Thread Hal Finney
Joanna - I've finally found the STM certs in the supplemental information on the TPM datasheet: www.st.com/internet/mcu/product/252378.jsp Infineon certs are available at http://www.infineon.com/tpm I didn't know about STM's having certs, thanks for the pointer. I don't know of any other TPM

Re: [tboot-devel] verifying module against policy failed

2013-03-29 Thread Hal Finney
You know, you don't have to mess around with this LCP stuff to get tboot working. I'd recommend ignoring this stuff when you're getting tboot working for the first time. Don't define any NV space. tboot will work fine without them. You'll see some error messages in the log, but they are harmless.

[tboot-devel] Intel(R) Trusted Execution Technology | Intel(R) Developer Zone

2013-04-20 Thread Hal Finney
tboot; I'm trying to get Jon McCune's flicker working, but that uses the same technology. Not very many laptops come with serial ports any more. But it has something called AMT which can theoretically emulate a serial port over ethernet. I need to learn how to do th