Conversation

Jarkko Sakkinen

Edited 19 days ago
I'm planning a new kernel feature based on patch set that I never finished:

https://lore.kernel.org/linux-integrity/aMwh95tMxB7sMEzy@kernel.org/

The gist is to harden selected AIKs, and perform signing and quotes through kernel, and filtered out from /dev/tpm0.

They'd be wrapped into keyring asymmetric keys. You can lock-in remote attestation pretty well then with UKI images having signed command-line.
0
0
1