Hong Hu wrote onĀ 2013-05-31: > Hi Jimmy, > > Thanks for you help. > > Now I can almost successfully run tboot on X220 tablet. The only problem > is the verification of module 0 (linux kernel in my case) which is > extended to PCR-18 failed. > > I followed instructions in docs/policy_v2.txt and lcptools/lcptools2.txt to create > the LCP and VLP. The only difference is the second step in creating VLP: > > The original version: > > 2. tb_polgen/tb_polgen --add --num 0 --pcr none --hash image --cmdline "the > command line for xen from grub.conf" --image /boot/xen.gz vl.pol > > and I changed it to : > > 2. tb_polgen/tb_polgen --add --num 0 --pcr none --hash image --cmdline > "intel_iommu=on root=UUID=XX(my uuid)XXX ro quiet splash vt.handoff=7" > --image /boot/vmlinuz-3.5.0.-31=generic vl.pol > > since there is no xen in my case. > > The result of module verification is that the verification for PCR 18 failed while > the verification for PCR 19 (initrd.img) successed. > > Is there any specific command to hash linux kernel other than xen? Any help will > be much appreciated.
Please send me me the exact command line you are using for generate the tb policy, as well as the grub config file. Jimmy
smime.p7s
Description: S/MIME cryptographic signature
------------------------------------------------------------------------------ Get 100% visibility into Java/.NET code with AppDynamics Lite It's a free troubleshooting tool designed for production Get down to code-level detail for bottlenecks, with <2% overhead. Download for free and get started troubleshooting in minutes. http://p.sf.net/sfu/appdyn_d2d_ap2
_______________________________________________ tboot-devel mailing list tboot-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/tboot-devel