From: Timo L. <tim...@ik...> - 2020-05-15 15:14:20
|
Hi, On Fri, 15 May 2020, Lukasz Hawrylko wrote: > Done. Thanks, I'll do some testing and ask for further feedback. Would it be possible to release a new version after some time with all these changes so that they would be part of the eventual Debian upload? Btw, can you recommend some tool for defining an NVRAM region that would allow me to specify the DRTM PCR values that need to match before it can be accessed? tpm_nvdefine -f works only with PCRs <= 15. I sent a patch last summer to fix this but the project does not seem to be very active and the patch appears to have been forgotten: https://www.mail-archive.com/tro...@li.../msg00684.html As far as I understand, the defindex tool in tboot does not let me specify PCR values either. I need this for forward-sealing of data across updates. -Timo |