On Mon, Nov 08, 2010 at 10:30:45AM -0500, Mimi Zohar wrote: > pcrlock=n extends the designated PCR 'n' with a random value, > so that a key sealed to that PCR may not be unsealed > again until after a reboot. Nice, but this seems very strange to me, since it has nothing to do with the key and could be done easially in userspace? Jason -- To unsubscribe from this list: send the line "unsubscribe linux-crypto" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html