Skip to content

Is there support for PCR >7? #445

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
yuannan opened this issue Mar 13, 2025 · 0 comments
Open

Is there support for PCR >7? #445

yuannan opened this issue Mar 13, 2025 · 0 comments

Comments

@yuannan
Copy link

yuannan commented Mar 13, 2025

I've tested the results of the PCR with tmp2-tool:tpm2_pcrread which told me that only PCR 4, 9, and 11 changed on booting a different system.

However, you cannot rely on PCR 4, 9, and 11 as they change along with whichever derivation you booted. Even if the derivation that you booted has only just changed 1 package not related to security.

I know lanzaboote is still in development, but I wanted to ask if there is anything currently that allows for booting different derivations without having to renroll PCR9 and 11.

I think there are currently 2 ways to do this:

  1. Just use PCR <7, this is not recommended according to a few sources.
  2. Automatically renroll PCR 9 and 11, however, I don't think this is possible as you have to boot them first.

Are there plans to add other registers to this so that the securely booted image can be along with firmware variables to ensure that the entire boot chain is secure?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant