Re: [tboot-devel] Questions about Launch Control Policies

2017-05-23 Thread Marco Vanotti
Thanks for your answer, Ning. I have been using tpm2.0-tools and tpm2.0-TSS to work with the TPM. They have been very useful so far :). I have a couple more questions regarding the Intel TXT Guide: The Intel TXT Guide (Appendix J "TPM NV") says that the NVRAM PO Index should have the following a

[tboot-devel] "Invalid RSDP" TXT Error

2017-05-23 Thread Marco Vanotti
Hi All! I am trying to get TXT working. I was able to get it to run with POLTYPE_ANY, however, as soon as I added a policy data file, I started getting *TXT error 0xC00020C1*, which for my SINIT ACM means "*Invalid RSDP*". (note that this error doesn't happen if I don't add the policy data module

Re: [tboot-devel] Questions about Launch Control Policies

2017-05-23 Thread Sun, Ning
Hi Marco, Thanks for the write-up, you got most of the answers correct for your questions. Both lcptools and lcptools-v2 folders (in tboot source package) are for LCP V2 on TPM 1.2 platforms Folder lcp-gen2 is for LCP V3 creation on TPM 2.0 platform, so far tboot does not provide tpm 2.0 tools

Re: [tboot-devel] Questions about Launch Control Policies

2017-05-23 Thread Marco Vanotti
Hi All! After reading a lot of documentation [*], I think I figured out the answers to some of the questions. I would like to confirm if what I think is correct. TBOOT sets up an environment and executes GETSEC[SENTER], which handles control over to the SINIT ACM. The SINIT ACM will measure the M