Re: [PATCH v5 17/25] powerpc/pseries: Implement signed update for PLPKS objects
From: Stefan Berger <stefanb@linux.ibm.com>
Date: 2023-01-31 16:31:55
Also in:
linux-integrity, lkml
From: Stefan Berger <stefanb@linux.ibm.com>
Date: 2023-01-31 16:31:55
Also in:
linux-integrity, lkml
On 1/31/23 01:39, Andrew Donnellan wrote:
From: Nayna Jain <nayna@linux.ibm.com> The Platform Keystore provides a signed update interface which can be used to create, replace or append to certain variables in the PKS in a secure fashion, with the hypervisor requiring that the update be signed using the Platform Key. Implement an interface to the H_PKS_SIGNED_UPDATE hcall in the plpks driver to allow signed updates to PKS objects. (The plpks driver doesn't need to do any cryptography or otherwise handle the actual signed variable contents - that will be handled by userspace tooling.) Signed-off-by: Nayna Jain <nayna@linux.ibm.com> [ajd: split patch, add timeout handling and misc cleanups] Co-developed-by: Andrew Donnellan <redacted> Signed-off-by: Andrew Donnellan <redacted> Signed-off-by: Russell Currey <redacted>
Reviewed-by: Stefan Berger <stefanb@linux.ibm.com>