Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2020-01-09 Thread Paul Moore (pmoore2) via tboot-devel
On Mon, 2019-12-23 at 21:20 +, Paul Moore (pmoore2) via tboot-devel wrote: > It appears that lcptools-v2 doesn't understand the "pconf" type ... I just added a new "pconf2" policy element type to lcptools-v2 so you can generate a LCP_PCONF_ELEMENT2 without having to resort to the lcp- gen2

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-12-23 Thread Paul Moore (pmoore2) via tboot-devel
On Wed, 2019-11-06 at 20:12 +, travis.gilb...@dell.com wrote: > > -Original Message- > > From: Paul Moore (pmoore2) > > Sent: Tuesday, November 5, 2019 19:28 > > To: Gilbert, Travis > > Cc: tboot-devel@lists.sourceforge.net > > Subject: Re: Creating a TXT/tboot policy suitable for a

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-16 Thread Dr. Greg
On Fri, Nov 15, 2019 at 07:40:58PM +, Paul Moore (pmoore2) via tboot-devel wrote: Hi, I hope the week is starting well for everyone. > Thanks Lukasz. I realize that might be a difficult discussion > internally, but I think it is the right thing to do at this point in > time. Hopefully, if

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-15 Thread Lukasz Hawrylko
: Wednesday, November 13, 2019 08:24 > > To: Gilbert, Travis; > > pmoo...@cisco.com > > > > Cc: > > tboot-devel@lists.sourceforge.net > > > > Subject: Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern > > system with TXT+TPM2 >

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-13 Thread Paul Moore (pmoore2) via tboot-devel
ge.net > > Subject: Re: [tboot-devel] Creating a TXT/tboot policy suitable for > > a modern system with TXT+TPM2 ... > > I'm a bit farther down the patch of sorting out the policy patches > > for the > > TXT/sig work, and as it currently stands it looks like th

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-13 Thread Paul Moore (pmoore2) via tboot-devel
ent: Friday, November 8, 2019 11:19 > > > To: > > > lukasz.hawry...@linux.intel.com > > > ; Gilbert, Travis > > > Cc: > > > tboot-devel@lists.sourceforge.net > > > > > > Subject: Re: [tboot-devel] Creating a TXT/tboot policy suitable &g

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-13 Thread Lukasz Hawrylko
) < > > pmoo...@cisco.com > > > > > Sent: Friday, November 8, 2019 11:19 > > To: > > lukasz.hawry...@linux.intel.com > > ; Gilbert, Travis > > Cc: > > tboot-devel@lists.sourceforge.net > > > > Subject: Re: [tboot-devel] Creating a T

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-08 Thread Travis.Gilbert
> -Original Message- > From: Paul Moore (pmoore2) > Sent: Friday, November 8, 2019 11:19 > To: lukasz.hawry...@linux.intel.com; Gilbert, Travis > Cc: tboot-devel@lists.sourceforge.net > Subject: Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern >

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-08 Thread Paul Moore (pmoore2) via tboot-devel
On Fri, 2019-11-08 at 12:47 +0100, Lukasz Hawrylko wrote: > For TPM2.0 LCP generation there is a Python tool lcp-gen2 that is > included in tboot's source code. To be honest I didn't try to generate > LCP with tboot's VLP inside but it should work. If not - this is a bug > and need to be fixed. >

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-08 Thread Lukasz Hawrylko
> > travis.gilb...@dell.com > > > wrote: > > > > > -Original Message- > > > > > From: Paul Moore (pmoore2) via tboot-devel > > > > de...@lists.sourceforge.net > > > > > > > > > > &g

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-06 Thread Travis.Gilbert
com; > > > tboot-devel@lists.sourceforge.net > > > Subject: [tboot-devel] Creating a TXT/tboot policy suitable for a > > > modern system with TXT+TPM2 > > > > > > > > > > > > Hi Lukasz, others, > > > > > > I'm in the proc

Re: [tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-05 Thread Paul Moore (pmoore2) via tboot-devel
t; tboot-devel@lists.sourceforge.net > > Subject: [tboot-devel] Creating a TXT/tboot policy suitable for a > > modern > > system with TXT+TPM2 > > > > > > > > Hi Lukasz, others, > > > > I'm in the process of working on the TXT/sig extensions

[tboot-devel] Creating a TXT/tboot policy suitable for a modern system with TXT+TPM2

2019-11-05 Thread Paul Moore (pmoore2) via tboot-devel
Hi Lukasz, others, I'm in the process of working on the TXT/sig extensions to the LCP but I'm running into problems using the tboot tools to create a working LCP as a baseline. Simply put, the instructions I've been able to find either in the sources, the mailing list archives, or through Google