Re: boot-time vtpm helper (was "Re: <void>")

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





On 8/3/23 05:06, Jarkko Sakkinen wrote:
On Thu Aug 3, 2023 at 11:25 AM EEST, Jarkko Sakkinen wrote:
Hi,

I have a working PoC for boot-time initialization of vtpm inside
tpm_vtpm_proxy. ATM, it uses the Linux firmware interface to load a ELF
binary for the vtpm, and delivers a communication end for the helper
process.

It is a great feature with the current narrow scope for continuous
integration. Obviously the scope could be later on extended to e.g.

Since VMs with vTPMs exist, which CI/CD environment would one use this in?

Where does the binary for the vtpm live when it's loaded with the firmware interface?

from unencrypted plain text to a vTPM living inside SGX enclave.

I would run swtpm inside an SGX enclave using Gramine.

Regards,
   Stefan


I could send an RFC of this, if there is wider interest for the
topic.

BR, Jarkko

I'm sorry, I'm trying learn aerc, and unfortunately forgot to add a subject.

BR, Jarkko



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Linux Kernel]     [Linux Kernel Hardening]     [Linux NFS]     [Linux NILFS]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux SCSI]

  Powered by Linux