[tboot-devel] Fix a bug in hash_module function

2018-02-26 Thread shiwan...@gohighsec.com
Hi, There is a bug in hash_module function. My machine is tpm2.0. As I have no machine of tpm1.2, I don't know whether it has the same issue for the machine of tpm1.2. When I set extpol=agile in the command line of tboot, module 1 can't be measured. Below is the related section of the TBOOT outp

Re: [tboot-devel] TXT SINIT ACM failure on power-cycling node

2018-02-26 Thread Rich Persaud
These are very likely to be OEM BIOS bugs - if you escalate to your server OEM, they can create fixes. We started testing TXT on enterprise clients almost 10 years ago. It took a while for OEMs (Dell, Lenovo, HP) to roll out TXT fixes, but they all did eventually. Server and workstation TXT m

Re: [tboot-devel] TXT SINIT ACM failure on power-cycling node

2018-02-26 Thread Jan Schermer
My HP z240 workstation occassionaly refuses to boot at all if I yank out the power cable while in TXT mode. Solution: leave power disconnected for >5 minutes, then reset BIOS (yes, really). I had similiar issues with Lenovo system. I don’t think OEMs test anything... Jan > On 26 Feb 2018, at

Re: [tboot-devel] TXT SINIT ACM failure on power-cycling node

2018-02-26 Thread Rich Persaud
On TXT-enabled vPro client devices (e.g. Dell 7040) that have been tested with OpenXT, Xen and OpenEmbedded measured launch [1], if you use the hardware power switch to perform a non-graceful shutdown of an operating system that was booted with TXT, the following will occur: (a) User presses