Thread (52 messages) 52 messages, 8 authors, 2023-09-07

Re: [RFC] IMA Log Snapshotting Design Proposal - aggregate

From: Ken Goldman <hidden>
Date: 2023-08-30 18:12:54
Also in: kexec, linux-integrity

On 8/1/2023 3:12 PM, Sush Shringarputale wrote:
- A user-mode process will trigger the snapshot by opening a file in SysFS
   say /sys/kernel/security/ima/snapshot (referred to as 
sysk_ima_snapshot_file
   here onwards).
- The Kernel will get the current TPM PCR values and PCR update counter [2]
   and store them as template data in a new IMA event "snapshot_aggregate".
If this is relying on a user-mode process, is there a concern that the 
process doesn't run. Might it be safer to have the kernel trigger the
snapshot.

PCR reads are not atomic, with each other and with event log appends. 
Is this an issue?

The PCR update counter can change between PCR reads.  What is its purpose?

What is the purpose of the snapshot aggregate?  Since the entire event 
log has to be retained and sent to the verifier, is the aggregate redundant?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help