[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v10 00/20] Automatic Disk Unlock with TPM2
From: |
Gary Lin |
Subject: |
Re: [PATCH v10 00/20] Automatic Disk Unlock with TPM2 |
Date: |
Fri, 12 Apr 2024 14:35:07 +0800 |
On Tue, Apr 09, 2024 at 04:30:32PM +0800, Gary Lin wrote:
> GIT repo for v10: https://github.com/lcp/grub2/tree/tpm2-unlock-v10
>
> This patch series is based on "Automatic TPM Disk Unlock"(*1) posted by
> Hernan Gatta to introduce the key protector framework and TPM2 stack
> to GRUB2, and this could be a useful feature for the systems to
> implement full disk encryption.
>
-->8--
>
> v10:
> - Fixing the coverity issues: CID 435775, CID 435771, CID 435770, CID
> 435769, CID 435767, CID 435761
> https://lists.gnu.org/archive/html/grub-devel/2024-02/txtKIuUb5lf3O.txt
> - Fixing the potential memory leak (CID 435775)
> - Removing the unnecessary grub_protect_get_grub_drive_for_file() from
> util/grub-protect.c (CID 435771)
> - Using the grub_tpm2_mu_TPM2B_*_Unmarshal functions to unmarshal the
> TPM2B structs instead of a generic grub_tpm2_mu_TPM2B_Unmarshal
> (CID 435770)
> - Fixing Null pointer dereference (CID 435769)
> - Adding bound checks to grub_tpm2_mu_TPML_DIGEST_Unmarshal()
> (CID 435767)
> - Improving the check for the return value of ftell() (CID 435761)
> - Adding a quick fix for CID 435762
> - Removing the empty ending line in tests/asn1_test.in
> - Fixing docs/grub-dev.texi and updating the libtasn1 patches in
> grub-core/lib/libtasn1-patches/
> - Merging all the TPM2 TSS stack patches into one to reduce the total
> patch number
> - Switching the default asymmetric algorithm from RSA2048 to
> TPM_ECC_NIST_P256 for the faster key generation
I forgot to update the help messages to reflect the change.
Will fix the help in v11...
> - Adding the fallback SRK templates to try a few more SRK types in case
> grub2 failed to associate the sealed key with the SRK in the persistent
> handle or the default SRK
> - Improving the test script to add tests for the persistent handle and
> the fallback SRKs
Gary Lin
- [PATCH v10 13/20] util/grub-protect: Add new tool, (continued)
- [PATCH v10 13/20] util/grub-protect: Add new tool, Gary Lin, 2024/04/09
- [PATCH v10 15/20] tpm2: Implement NV index, Gary Lin, 2024/04/09
- [PATCH v10 14/20] tpm2: Support authorized policy, Gary Lin, 2024/04/09
- [PATCH v10 16/20] cryptodisk: Fallback to passphrase, Gary Lin, 2024/04/09
- [PATCH v10 18/20] diskfilter: look up cryptodisk devices first, Gary Lin, 2024/04/09
- [PATCH v10 17/20] cryptodisk: wipe out the cached keys from protectors, Gary Lin, 2024/04/09
- [PATCH v10 19/20] tpm2: Enable tpm2 module for grub-emu, Gary Lin, 2024/04/09
- [PATCH v10 20/20] tests: Add tpm2_test, Gary Lin, 2024/04/09
- Re: [PATCH v10 00/20] Automatic Disk Unlock with TPM2,
Gary Lin <=