Skip to content

Events logged into PCR7 should not alter the order #43

@bgartzi

Description

@bgartzi

The TCG PC Client Specific Platform Firmware Profile Specification, v1.06-rev52 when this issue is being opened, states:

  • A list of secure boot variables that are logged into PCR7, in an order.
  • And also points out that the order is actually relevant:
  1. Before executing any code not cryptographically authenticated as being provided by the Platform
    Manufacturer, the Platform Manufacturer firmware MUST measure the Secure Boot Variables as defined
    above, in the order listed using the defined event types.

So the firmware should respect that, no matter which is the cloud vendor serving it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions