Re: [RFC] IMA Log Snapshotting Design Proposal - aggregate

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 8/1/2023 3:12 PM, Sush Shringarputale wrote:
- A user-mode process will trigger the snapshot by opening a file in SysFS
  say /sys/kernel/security/ima/snapshot (referred to as sysk_ima_snapshot_file
   here onwards).
- The Kernel will get the current TPM PCR values and PCR update counter [2]
   and store them as template data in a new IMA event "snapshot_aggregate".

If this is relying on a user-mode process, is there a concern that the process doesn't run. Might it be safer to have the kernel trigger the
snapshot.

PCR reads are not atomic, with each other and with event log appends. Is this an issue?

The PCR update counter can change between PCR reads.  What is its purpose?

What is the purpose of the snapshot aggregate? Since the entire event log has to be retained and sent to the verifier, is the aggregate redundant?


_______________________________________________
kexec mailing list
kexec@xxxxxxxxxxxxxxxxxxx
http://lists.infradead.org/mailman/listinfo/kexec




[Index of Archives]     [LM Sensors]     [Linux Sound]     [ALSA Users]     [ALSA Devel]     [Linux Audio Users]     [Linux Media]     [Kernel]     [Gimp]     [Yosemite News]     [Linux Media]

  Powered by Linux