Re: [PATCH v1.2 3/4] keys: add new trusted key-type

From: Jason Gunthorpe
Date: Mon Nov 08 2010 - 12:09:56 EST


On Mon, Nov 08, 2010 at 10:30:45AM -0500, Mimi Zohar wrote:

> pcrlock=n extends the designated PCR 'n' with a random value,
> so that a key sealed to that PCR may not be unsealed
> again until after a reboot.

Nice, but this seems very strange to me, since it has nothing to do
with the key and could be done easially in userspace?

Jason
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/