[tpm2] Re: Is the tpm2_create command safe against sniffing attacks?
joseph at zeronsoftn.com
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <[email protected]> |
"salted session" was the keyword I was looking for! Really thank you :) 화요일, 03 8월 2021, 03:59오전 +09:00 발신 Kenneth Goldman kgoldman(a)us.ibm.com : >"Steven Clark" < davolfman(a)gmail.com> wrote on 08/02/2021 01:26:56 PM: > > I think it may be an optional standard but my TPM has some certs > permanently stored in nv-indices in the 0x1c0000x range that can be > checked against the manufacturer cert. I haven't learned how to > leverage those into trusted parameter encryption keys yet but they > should be able to verify there's a real TPM at the other end at the > very least (and more if you learn to use them correctly). > >The EK certificates in NV are in theory optional, but every TPM >I have encountered has them. > >Checking the certificate against the manufacturer's CA is >a standard crypto library function. > >Once you have an authentic EK, create a salted session using >the EK. > >Once you have the salted session, set the encrypt and/or decrypt bit >when running the command. > >Underneath, there's some complicated crypto, but it's all >hidden from the application. > >_______________________________________________ >tpm2 mailing list -- tpm2(a)lists.01.org >To unsubscribe send an email to tpm2-leave(a)lists.01.org >%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm
(text/html, 2.6 KB)
<html><head></head><body><p style="margin-top: 0px;" dir="ltr">"salted session" was the keyword I was looking for!<br> Really thank you :)</p> 화요일, 03 8월 2021, 03:59오전 +09:00 발신 Kenneth Goldman <a href="mailto:[email protected]">[email protected]</a>:<br><br><blockquote id="mail-app-auto-quote" cite="16279307420000005606" style="border-left:1px solid #FC2C38; margin:0px 0px 0px 10px; padding:0px 0px 0px 10px;"> <div class="js-helper js-readmsg-msg"> <style type="text/css"></style> <div> <base target="_self" href="https://e-aj.my.com/"> <div id="style_16279307420000005606_BODY"><div class="cl_938656"><p><tt><font size="2">"Steven Clark" <<a href="mailto:[email protected]">[email protected]</a>> wrote on 08/02/2021 01:26:56 PM:<br><br>> I think it may be an optional standard but my TPM has some certs <br>> permanently stored in nv-indices in the 0x1c0000x range that can be <br>> checked against the manufacturer cert. I haven't learned how to <br>> leverage those into trusted parameter encryption keys yet but they <br>> should be able to verify there's a real TPM at the other end at the <br>> very least (and more if you learn to use them correctly).</font></tt><br><tt><font size="2"><br>The EK certificates in NV are in theory optional, but every TPM</font></tt><br><tt><font size="2">I have encountered has them.</font></tt><br><br><tt><font size="2">Checking the certificate against the manufacturer's CA is</font></tt><br><tt><font size="2">a standard crypto library function.</font></tt><br><br><tt><font size="2">Once you have an authentic EK, create a salted session using</font></tt><br><tt><font size="2">the EK.</font></tt><br><br><tt><font size="2">Once you have the salted session, set the encrypt and/or decrypt bit</font></tt><br><tt><font size="2">when running the command.</font></tt><br><br><tt><font size="2">Underneath, there's some complicated crypto, but it's all</font></tt><br><tt><font size="2">hidden from the application.</font></tt><br> <br> </p></div></div> <div>_______________________________________________<br> tpm2 mailing list -- <a href="mailto:[email protected]">[email protected]</a><br> To unsubscribe send an email to <a href="mailto:[email protected]">[email protected]</a><br> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</div> <base target="_self" href="https://e-aj.my.com/"> </div> </div> </blockquote> <div><br><br><br><img src="https://mail.zeronsoftn.com/mthumbnail/4e645b05-f948-4090-8a7d-a1196f1fafbe.png" style="max-height: 32px"></div></body></html>