Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 11:05 AM, Stefan Berger wrote: Hi!  I am sending this email to solicit input on the choice of the PCR banks to enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for SHA{1,256,384,512}. The downside of this is that running the TPM 2 with so many PCR banks has a perfo

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 12:11 PM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: On 06/25/2018 11:29 AM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: On 06/25/2018 11:18 AM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@li

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 12:10 PM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2018 at 12:08:34PM -0400, Stefan Berger wrote: On 06/25/2018 11:59 AM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2018 at 11:56:24AM -0400, Stefan Berger wrote: On 06/25/2018 11:25 AM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Dr. David Alan Gilbert
* Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > On 06/25/2018 11:29 AM, Dr. David Alan Gilbert wrote: > > * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > > > On 06/25/2018 11:18 AM, Dr. David Alan Gilbert wrote: > > > > * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > > > > > Hi! >

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Daniel P . Berrangé
On Mon, Jun 25, 2018 at 12:08:34PM -0400, Stefan Berger wrote: > On 06/25/2018 11:59 AM, Daniel P. Berrangé wrote: > > On Mon, Jun 25, 2018 at 11:56:24AM -0400, Stefan Berger wrote: > > > On 06/25/2018 11:25 AM, Daniel P. Berrangé wrote: > > > > On Mon, Jun 25, 2018 at 11:05:55AM -0400, Stefan Berg

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 11:59 AM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2018 at 11:56:24AM -0400, Stefan Berger wrote: On 06/25/2018 11:25 AM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2018 at 11:05:55AM -0400, Stefan Berger wrote: Hi!  I am sending this email to solicit input on the choice of th

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Daniel P . Berrangé
On Mon, Jun 25, 2018 at 11:56:24AM -0400, Stefan Berger wrote: > On 06/25/2018 11:25 AM, Daniel P. Berrangé wrote: > > On Mon, Jun 25, 2018 at 11:05:55AM -0400, Stefan Berger wrote: > > > Hi! > > > > > >  I am sending this email to solicit input on the choice of the PCR banks > > > to > > > enab

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 11:25 AM, Daniel P. Berrangé wrote: On Mon, Jun 25, 2018 at 11:05:55AM -0400, Stefan Berger wrote: Hi!  I am sending this email to solicit input on the choice of the PCR banks to enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for SHA{1,256,384,512}. The downside o

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 11:29 AM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: On 06/25/2018 11:18 AM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: Hi!  I am sending this email to solicit input on the choice of the PCR banks to

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Dr. David Alan Gilbert
* Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > On 06/25/2018 11:18 AM, Dr. David Alan Gilbert wrote: > > * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > > > Hi! > > > > > >  I am sending this email to solicit input on the choice of the PCR banks > > > to > > > enable for swtpm's TPM

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Daniel P . Berrangé
On Mon, Jun 25, 2018 at 11:05:55AM -0400, Stefan Berger wrote: > Hi! > >  I am sending this email to solicit input on the choice of the PCR banks to > enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for > SHA{1,256,384,512}. The downside of this is that running the TPM 2 with so > m

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
On 06/25/2018 11:18 AM, Dr. David Alan Gilbert wrote: * Stefan Berger (stef...@linux.vnet.ibm.com) wrote: Hi!  I am sending this email to solicit input on the choice of the PCR banks to enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for SHA{1,256,384,512}. The downside of this

Re: [Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Dr. David Alan Gilbert
* Stefan Berger (stef...@linux.vnet.ibm.com) wrote: > Hi! > >  I am sending this email to solicit input on the choice of the PCR banks to > enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for > SHA{1,256,384,512}. The downside of this is that running the TPM 2 with so > many PCR ban

[Qemu-devel] Choosing PCR banks for swtpm's TPM 2

2018-06-25 Thread Stefan Berger
Hi!  I am sending this email to solicit input on the choice of the PCR banks to enable for swtpm's TPM 2. I have currently enabled 4 PCR banks for SHA{1,256,384,512}. The downside of this is that running the TPM 2 with so many PCR banks has a performance impact when the Linux integrity measur