Hong Hu wrote onĀ 2013-05-31:
> Hi Jimmy,
> 
> Thanks for you help.
> 
> Now I can almost successfully run tboot on X220 tablet. The only problem
> is the verification of module 0 (linux kernel in my case) which is
> extended to PCR-18 failed.
> 
> I followed instructions in docs/policy_v2.txt and lcptools/lcptools2.txt
to create
> the LCP and VLP. The only difference is the second step in creating VLP:
> 
> The original version:
> 
> 2.  tb_polgen/tb_polgen --add --num 0 --pcr none --hash image --cmdline
"the
> command line for xen from grub.conf" --image /boot/xen.gz vl.pol
> 
> and I changed it to :
> 
> 2.   tb_polgen/tb_polgen --add --num 0 --pcr none --hash image --cmdline
> "intel_iommu=on root=UUID=XX(my uuid)XXX ro quiet splash vt.handoff=7"
> --image /boot/vmlinuz-3.5.0.-31=generic vl.pol
> 
> since there is no xen in my case.
> 
> The result of module verification is that the verification for PCR 18
failed while
> the verification for PCR 19 (initrd.img) successed.
> 
> Is there any specific command to hash linux kernel other than xen? Any
help will
> be much  appreciated.

Please send me me the exact command line you are using for generate the tb
policy, as well as the grub config file.

Jimmy

Attachment: smime.p7s
Description: S/MIME cryptographic signature

------------------------------------------------------------------------------
Get 100% visibility into Java/.NET code with AppDynamics Lite
It's a free troubleshooting tool designed for production
Get down to code-level detail for bottlenecks, with <2% overhead.
Download for free and get started troubleshooting in minutes.
http://p.sf.net/sfu/appdyn_d2d_ap2
_______________________________________________
tboot-devel mailing list
tboot-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/tboot-devel

Reply via email to