Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

efi: Add profiles for PCRs 0 and 2 #299

Merged

Conversation

chrisccoulson
Copy link
Collaborator

@chrisccoulson chrisccoulson commented Apr 29, 2024

This adds profiles for PCR0 (platform firmware) and PCR2 (host firmware that
runs from adapter cards or firmware that runs on embedded controllers)

@chrisccoulson chrisccoulson marked this pull request as ready for review April 29, 2024 20:58
This adds profiles for PCR0 (platform firmware) and PCR2 (host
firmware that runs from adapter cards or firmware that runs on
embedded controllers)
Copy link
Collaborator

@pedronis pedronis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks good, Is the plan that we should start including these in profiles going forward? a bit more motivation in the summary would be useful

@chrisccoulson
Copy link
Collaborator Author

this looks good, Is the plan that we should start including these in profiles going forward? a bit more motivation in the summary would be useful

The goal is that an eventual PR that implements the pre-install checks will return an options that contains the optimal set of TCG defined PCRs, which may or many not include these new profiles depending on the device configuration. There will be some additional options to control this, such as selecting "optimal" configuration or "most secure".

Copy link
Collaborator

@pedronis pedronis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 but please add some of

The goal is that an eventual PR that implements the pre-install checks will return an options that contains the optimal set of TCG defined PCRs, which may or many not include these new profiles depending on the device configuration. There will be some additional options to control this, such as selecting "optimal" configuration or "most secure".

to the description

@chrisccoulson chrisccoulson merged commit 121a1da into canonical:master May 30, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants