Thread (30 messages) 30 messages, 5 authors, 2018-03-16

Re: [PATCH] security: Fix IMA Kconfig for dependencies on ARM64

From: Mimi Zohar <hidden>
Date: 2018-03-07 18:56:06
Also in: linux-security-module, lkml

On Wed, 2018-03-07 at 11:51 -0700, Jason Gunthorpe wrote:
On Tue, Mar 06, 2018 at 11:26:26PM -0600, Jiandi An wrote:
quoted
TPM_CRB driver is the TPM support for ARM64.  If it
is built as module, TPM chip is registered after IMA
init.  tpm_pcr_read() in IMA driver would fail and
display the following message even though eventually
there is TPM chip on the system:

ima: No TPM chip found, activating TPM-bypass! (rc=-19)

Fix IMA Kconfig to select TPM_CRB so TPM_CRB driver is
built in kernel and initializes before IMA driver.

Signed-off-by: Jiandi An <redacted>
 security/integrity/ima/Kconfig | 1 +
 1 file changed, 1 insertion(+)
diff --git a/security/integrity/ima/Kconfig b/security/integrity/ima/Kconfig
index 35ef693..6a8f677 100644
+++ b/security/integrity/ima/Kconfig
@@ -10,6 +10,7 @@ config IMA
 	select CRYPTO_HASH_INFO
 	select TCG_TPM if HAS_IOMEM && !UML
 	select TCG_TIS if TCG_TPM && X86
+	select TCG_CRB if TCG_TPM && ACPI
 	select TCG_IBMVTPM if TCG_TPM && PPC_PSERIES
 	help
 	  The Trusted Computing Group(TCG) runtime Integrity
This seems really weird, why are any specific TPM drivers linked to
IMA config, we have lots of drivers..

I don't think I've ever seen this pattern in Kconfig before?
As you've seen by the current discussions, the TPM driver needs to be
initialized prior to IMA.  Otherwise IMA goes into TPM-bypass mode.
 That implies that the TPM must be builtin to the kernel, and not as a
kernel module.

Mimi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help