Re: [PATCH 1/4] integrity: TPM internel kernel interface

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Kenneth Goldman <kgoldman@...>
Cc: Peter Dolding <oiaohm@...>, <linux-kernel@...>, <linux-security-module@...>
Date: Friday, August 15, 2008 - 3:22 pm

On Fri, 15 Aug 2008 14:50:01 EDT, Kenneth Goldman said:

Well, on a dual/quad core/socket/whatever system, a failing processor
can be downed and the system keep going.  On a NUMA box, you can yank a
node with a bad memory controller after you take it down.  Similarly for
a disk controller if you have more than one, and the failed one isn't
critical for system operation.

And the TPM chip is more like a USB controller, in that there's a *high*
degree of probability that the system will still be able to run even if it
fails or goes insane (consider that on my laptop, the TPM driver was broken
for a while, and I was still ableto work).  So you need to write code to
do things like detect TPM downage or insanity, decide what to do on the
kernel level, what to reflect up to any security modules running in
userspace, etc....
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Sat Aug 9, 2:46 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Tue Aug 12, 3:30 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Tue Aug 12, 4:57 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Mon Aug 18, 11:01 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Peter Dolding, (Fri Aug 15, 6:37 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Fri Aug 15, 2:50 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, , (Fri Aug 15, 3:22 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 9:58 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 9:46 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 12:39 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Wed Aug 13, 10:45 am)