auth: support policy session hash in PCR authorization#3597
Open
chench246 wants to merge 1 commit into
Open
Conversation
Extend the pcr: authorization mini-language with an optional policy session hash suffix so implicit PCR policy sessions can use a non-default hash algorithm, for example pcr:sm3_256:0,2@sm3_256. This keeps the existing pcr:<pcr-spec>[=<raw-pcr-file>] behavior unchanged when no suffix is present, and avoids adding command-specific authorization options. Signed-off-by: chench246 <chench246@hotmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The implicit policy session created for
pcr:authorization currently uses the default session hash algorithm. When a policy digest was created with a different hash algorithm, the TPM rejects the authorization with TPM_RC_POLICY_FAIL.Extend the
pcr:authorization mini-language to allow selecting the hash algorithm used by the implicit PCR policy session:For example:
This allows a PCR policy whose digest was created with a non-default hash algorithm, such as sm3_256, to be satisfied through -P/--auth. The implicit session hash is only overridden when the optional
@<policy-session-hash>suffix is supplied.