Re: [PATCH] KEYS: trusted_tpm2: Only check options->keyhandle for ASN.1

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, 2024-05-25 at 15:36 +0300, Jarkko Sakkinen wrote:
> tpm2_load_cmd incorrectly checks options->keyhandle also for the
> legacy format, as also implied by the inline comment. Check
> options->keyhandle when ASN.1 is loaded.

No that's not right.  keyhandle must be specified for the old format,
because it's just the two private/public blobs and doesn't know it's
parent. Since tpm2_key_decode() always places the ASN.1 parent into
options->keyhandle, the proposed new code is fully redundant (options-
>keyhandle must be non zero if the ASN.1 parsed correctly) but it loses
the check that the loader must specify it for the old format.

What the comment above the code you removed means is that the keyhandle
must be non zero here, either extracted from the ASN.1 for the new
format or specified on the command line for the old.

James





[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Linux Kernel]     [Linux Kernel Hardening]     [Linux NFS]     [Linux NILFS]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux SCSI]

  Powered by Linux