ksummit.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
From: James Bottomley <James.Bottomley@HansenPartnership.com>
To: Andy Lutomirski <luto@amacapital.net>
Cc: Mark Brown <broonie@sirena.org.uk>,
	"ksummit-discuss@lists.linuxfoundation.org"
	<ksummit-discuss@lists.linuxfoundation.org>
Subject: Re: [Ksummit-discuss] Last minute nominations: mcgrof and toshi
Date: Wed, 27 Jul 2016 15:50:42 -0400	[thread overview]
Message-ID: <1469649042.27356.109.camel@HansenPartnership.com> (raw)
In-Reply-To: <CALCETrXg6+jFWmycaKu2o=BbDytn+vyGxxY5AQTCo0RoxySvCw@mail.gmail.com>

On Wed, 2016-07-27 at 12:20 -0700, Andy Lutomirski wrote:
> On Wed, Jul 27, 2016 at 12:00 PM, James Bottomley
> <James.Bottomley@hansenpartnership.com> wrote:
> > On Wed, 2016-07-27 at 10:57 -0700, Andy Lutomirski wrote:
> > > On Wed, Jul 27, 2016 at 9:14 AM, James Bottomley
> > > <James.Bottomley@hansenpartnership.com> wrote:
> > > > On Wed, 2016-07-27 at 16:37 +0100, David Howells wrote:
> > > > > James Bottomley <James.Bottomley@HansenPartnership.com>
> > > > > wrote:
> > > > > 
> > > > > >    3. Integration with existing key management
> > > > > > infrastructures.
> > > > > >   The issue
> > > > > >       here is things like the gnome keyring and the TPM. 
> > > > > >  The
> > > > > > TPM is a
> > > > > >       particularly thorny problem: as a key store, the TPM
> > > > > > has
> > > > > > a very
> > > > > >       limited storage space, so something has effectively
> > > > > > to
> > > > > > swap keys in
> > > > > >       and out as they're used.  This function is currently
> > > > > > performed by a
> > > > > >       userspace stack called the TSS.  However, the kernel
> > > > > > use
> > > > > > of the TPM
> > > > > >       effectively steals the nvram resource behind the
> > > > > > manager's back and
> > > > > >       can lead to resource starvation issues in the TPM and
> > > > > > unexpected
> > > > > >       responses back to the user space TSS.  If the kernel
> > > > > > wants to use
> > > > > >       TPM keys, it needs either to request them properly
> > > > > > from
> > > > > > the TSS or
> > > > > >       we need to pull TPM key management fully into the
> > > > > > kernel
> > > > > > and make
> > > > > >       the TSS use it.
> > > > > 
> > > > > I have partial patches for this, but they're against an old, 
> > > > > pre-tpm2 version of the kernel and need updating.  They 
> > > > > expose TPM keys as a subtype of the asymmetric key type.
> > > > 
> > > > Heh, you really know how to poke a sore spot, since we 
> > > > effectively have two TSSs in Linux: trousers the TPM 1.1 and 
> > > > 1.2 compatible one and ibmtpm20tss for TPM 2.0.  I don't think 
> > > > we have an answer on how we make them work compatibly.  I'm 
> > > > sort of hoping to get some coherence in the TPM Microconference
> > > > at Plumbers
> > > > 
> > > > http://www.linuxplumbersconf.org/2016/ocw/events/LPC2016/tracks
> > > > /585
> > > > 
> > > > However, if we do an upcall to the TSS, then we can't use TPM 
> > > > keys in the pre-boot and have difficulty using them in initrd
> > > > environments, which seems like it might cause problems.
> > > > 
> > > 
> > > I think this nuts.  The kernel should arbitrate use of the TPM's 
> > > key slots and handle context switching.  Doing it in userspace is 
> > > a terrible idea for this and other reasons. 
> > 
> > Hey, I don't disagree, but the user space TSS would have to be 
> > updated as well if we did this.  Right at the moment, the tpmd in 
> > the kernel is a straight TPM command pass through.  We'd need a 
> > more complex interface if the kernel is actually going to manage 
> > TPM key slots.   I think it means quite a big code change, both in 
> > the kernel and for the new interface and for the TSS.
> 
> I admit it's been a while since I read the TPM protocol specs, but I
> think it might be doable without breaking compatibility.  We could
> pretend to pass commands through but instead either emulate a TPM 
> with a whole lot of slots or emulate a TPM with somewhat fewer slots 
> than the real one and remap the slot numbering as needed.

Been there, done that, got the flashing bow tie from our TPM experts as
a "here's a shiny thing small kernel person, you play with it while we
solve the hard security problems" prize.

The reason it doesn't work as simply is that TPM commands mostly
require authentication and may be encrypted (transport wrapped in TPM
speak).  For commands which manipulate keys, the key handle may be part
of the HMAC authentication verifier, so we can't simply replace the key
handle without the HMAC failing to verify or they're encrypted, in
which case we can't even see what the handle is.  The reason the TSS
can do this is that it generates the HMAC and even the wrapping.  It's
hard to see how to solve this without either pulling the whole TSS into
the kernel (yuk) or having a sideband API where the kernel and the TSS
co-operate on key slot handling.

> > Anyway, I put it on the proposed agenda for the Plumbers TPM
> > discussions:
> > 
> > http://wiki.linuxplumbersconf.org/2016:tpms
> 
> If I manage to still be in town, I'll try to make it to that session.

Great, thanks!

James


> --Andy
> _______________________________________________
> Ksummit-discuss mailing list
> Ksummit-discuss@lists.linuxfoundation.org
> https://lists.linuxfoundation.org/mailman/listinfo/ksummit-discuss
> 

  reply	other threads:[~2016-07-27 19:50 UTC|newest]

Thread overview: 101+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-08-04 15:26 Luis R. Rodriguez
2015-08-04 22:20 ` Toshi Kani
2016-07-15 19:50 ` Mimi Zohar
2016-07-15 19:57   ` Mimi Zohar
2016-07-16  0:52     ` Mark Brown
2016-07-26 14:42       ` David Woodhouse
2016-07-27 14:04         ` [Ksummit-discuss] [TECH TOPIC] Signature management - keys, modules, firmware, was: " Jason Cooper
2016-07-27 14:58           ` Mark Rutland
2016-07-27 18:17           ` Stephen Hemminger
2016-07-27 18:36             ` Andy Lutomirski
2016-07-29 12:29           ` Ben Hutchings
2016-08-05 17:16             ` Mimi Zohar
2016-08-05 18:24               ` Ben Hutchings
2016-08-02 12:54           ` Linus Walleij
2016-08-02 14:00             ` Jason Cooper
2016-08-02 14:09               ` David Woodhouse
     [not found]               ` <CALCETrUjn7TeGbS4TQ+OFih-nby2Rh54i5177MOwqjTYDBMO=A@mail.gmail.com>
     [not found]                 ` <CALCETrU6aQ5PR_+M7QHkTWos6i6vVS2nvEQDwr5ktBkWu-5MKw@mail.gmail.com>
     [not found]                   ` <CALCETrW8uRK4cuQ+B6NPcO0pY-=-HRDf4LZk4xv2QdPzNEvMCg@mail.gmail.com>
     [not found]                     ` <CALCETrW_mQLmR6g_Ar8Nnpr7CRFZhth=Hj9C901Gj7_WSp=yEQ@mail.gmail.com>
2016-08-02 14:53                       ` Andy Lutomirski
2016-08-02 14:13             ` James Bottomley
2016-08-03  9:47               ` Linus Walleij
2016-08-03 10:00                 ` Jiri Kosina
2016-08-03 10:28                 ` Jani Nikula
2016-08-03 10:41                   ` Linus Walleij
2016-08-03 11:18                     ` Jani Nikula
2016-08-03 15:19                     ` Jason Cooper
2016-08-12 12:38                 ` Vinod Koul
2016-08-12 12:39                   ` David Woodhouse
2016-08-12 12:54                   ` Andy Lutomirski
2016-08-12 13:00                     ` David Woodhouse
2016-08-12 13:12                     ` Vinod Koul
2016-07-27 14:08         ` David Howells
2016-07-27 14:10           ` Ard Biesheuvel
2016-07-27 14:23             ` Mark Brown
2016-07-27 15:06         ` [Ksummit-discuss] " James Bottomley
2016-08-01 10:22           ` Johannes Berg
2016-07-27 15:37         ` David Howells
2016-07-27 16:14           ` James Bottomley
2016-07-27 17:57             ` Andy Lutomirski
2016-07-27 19:00               ` James Bottomley
2016-07-27 19:20                 ` Andy Lutomirski
2016-07-27 19:50                   ` James Bottomley [this message]
2016-07-27 16:07         ` David Howells
2016-07-27 16:25           ` James Bottomley
2016-07-27 16:10         ` David Howells
2016-07-27 16:14         ` David Howells
2016-07-27 16:28           ` James Bottomley
2016-07-27 16:36             ` James Bottomley
2016-07-27 17:20               ` Luis R. Rodriguez
2016-07-27 17:51                 ` James Bottomley
2016-07-27 18:57                   ` Luis R. Rodriguez
2016-07-27 19:37               ` Mimi Zohar
2016-07-27 20:09                 ` Andy Lutomirski
2016-07-27 22:54                   ` Mimi Zohar
2016-07-27 23:15                     ` Andy Lutomirski
2016-07-28  3:17                       ` Mimi Zohar
2016-07-28  3:29                         ` Andy Lutomirski
2016-07-28 16:57                   ` Jason Cooper
2016-07-29 22:10                     ` Mimi Zohar
2016-07-29 22:25                       ` Andy Lutomirski
2016-07-30 16:36                         ` Luis R. Rodriguez
2016-07-31  3:08                           ` Mimi Zohar
2016-07-31  3:09                             ` Andy Lutomirski
2016-07-31 15:31                               ` Mimi Zohar
2016-07-31 16:19                                 ` Andy Lutomirski
2016-07-31 17:28                                   ` Mimi Zohar
2016-07-31 18:20                                     ` Andy Lutomirski
2016-08-01  1:52                                       ` Mimi Zohar
2016-08-01 17:29                                       ` Luis R. Rodriguez
2016-08-01 17:59                                         ` Andy Lutomirski
2016-08-01 20:23                                           ` Luis R. Rodriguez
2016-08-01 20:37                                             ` Andy Lutomirski
2016-08-01 20:57                                               ` Luis R. Rodriguez
2016-08-01 21:14                                                 ` Andy Lutomirski
2016-08-01 22:56                                                   ` Jason Cooper
2016-08-01 23:12                                                     ` Andy Lutomirski
2016-08-02  0:33                                                   ` James Bottomley
     [not found]                                                     ` <CALCETrXHfUULy-EB13Kbkjwco-2UVgsuRsG+OicZT6_uOkzeqA@mail.gmail.com>
     [not found]                                                       ` <CALCETrWqpQV1AyxVx5eTkJiOe3t7ZFpSAuN2RG3JNHD-gqm0uA@mail.gmail.com>
2016-08-02  0:48                                                         ` Andy Lutomirski
2016-08-02  1:13                                                           ` James Bottomley
2016-08-02  1:23                                                             ` Andy Lutomirski
2016-08-02 18:12                                                               ` James Bottomley
2016-08-01 22:21                                           ` Mimi Zohar
2016-08-01 22:36                                             ` Andy Lutomirski
2016-08-01 23:02                                               ` Mimi Zohar
2016-08-01 23:04                                               ` Jason Cooper
2016-08-01 23:13                                                 ` Andy Lutomirski
2016-08-01 23:30                                                   ` Jason Cooper
     [not found]                                                     ` <CALCETrWDsMdU2-AWQC4wYvotnNd2ydWT15Ckq0nZaNRJZOtZ-g@mail.gmail.com>
     [not found]                                                       ` <CALCETrW-P8+yGuEgM2BT+aCfZqJ=ekB2Xsz+4xhWtdRpprJHNw@mail.gmail.com>
2016-08-01 23:45                                                         ` Andy Lutomirski
2016-08-02 12:20                                                           ` Jason Cooper
     [not found]                                                             ` <CALCETrVEY=opRPGKy=P9h8s+TC_K19WnBJ2svXT+=_FnqRF1Mw@mail.gmail.com>
     [not found]                                                               ` <CALCETrVZtn_SmeN1YX9_+2g+bEAHsfJJ7KQH7-eC_mU3O+0x2w@mail.gmail.com>
2016-08-02 15:07                                                                 ` Andy Lutomirski
2016-08-03 16:44                                                                   ` Jason Cooper
2016-08-03 17:20                                                                     ` Andy Lutomirski
2016-08-03 17:50                                                                       ` Jason Cooper
2016-08-01 17:15                                   ` Luis R. Rodriguez
2016-08-02 18:55                   ` Andy Lutomirski
2016-08-02 19:02                     ` Ard Biesheuvel
2016-08-02 19:08                       ` Andy Lutomirski
2016-08-02 19:14                         ` Ard Biesheuvel
2016-08-02 19:17                           ` Andy Lutomirski
2016-08-02 19:20                             ` Ard Biesheuvel
2016-08-02 20:22                               ` Ard Biesheuvel
2016-07-29 12:43               ` Ben Hutchings
2016-07-29 17:57                 ` Mimi Zohar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1469649042.27356.109.camel@HansenPartnership.com \
    --to=james.bottomley@hansenpartnership.com \
    --cc=broonie@sirena.org.uk \
    --cc=ksummit-discuss@lists.linuxfoundation.org \
    --cc=luto@amacapital.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox