testing: Switched PTS measurements to /usr/sbin

Due to Debian 10 linking /bin to /usr/bin which drastically
increased the number of files in /bin, the PTS measurement
was switched to /usr/sbin with a lesser number of files.
This commit is contained in:
Andreas Steffen
2021-03-23 10:54:48 +01:00
parent f412c97648
commit 737f7fce51
13 changed files with 40 additions and 13 deletions
+2 -2
View File
@@ -1731,7 +1731,7 @@ INSERT INTO policies ( /* 10 */
INSERT INTO policies ( /* 11 */ INSERT INTO policies ( /* 11 */
type, name, dir, rec_fail, rec_noresult type, name, dir, rec_fail, rec_noresult
) VALUES ( ) VALUES (
8, 'Get /bin', 1, 0, 0 8, 'Get /usr/sbin', 12, 0, 0
); );
INSERT INTO policies ( /* 12 */ INSERT INTO policies ( /* 12 */
@@ -1761,7 +1761,7 @@ INSERT INTO policies ( /* 15 */
INSERT INTO policies ( /* 16 */ INSERT INTO policies ( /* 16 */
type, name, dir, rec_fail, rec_noresult type, name, dir, rec_fail, rec_noresult
) VALUES ( ) VALUES (
9, 'Measure /bin', 1, 2, 2 9, 'Measure /usr/sbin', 12, 2, 2
); );
INSERT INTO policies ( /* 17 */ INSERT INTO policies ( /* 17 */
@@ -11,8 +11,8 @@ protocol defined by <b>RFC 5792 PA-TNC</b>.
<em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front <em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front
to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an
<em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference <em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference
measurement on all files in the <b>/bin</b> directory. <b>carol</b> is then prompted to measurement on all files in the <b>/usr/sbin</b> directory. <b>carol</b> is then prompted to
measure a couple of individual files and the files in the <b>/bin</b> directory as measure a couple of individual files and the files in the <b>/usr/sbin</b> directory as
well as to get metadata on the <b>/etc/tnc_confg</b> configuration file. well as to get metadata on the <b>/etc/tnc_confg</b> configuration file.
<p> <p>
<b>carol</b> passes the health test and <b>dave</b> fails because IP forwarding is <b>carol</b> passes the health test and <b>dave</b> fails because IP forwarding is
@@ -12,6 +12,11 @@ charon-systemd {
pts = 3 pts = 3
} }
} }
plugins {
eap-ttls {
max_message_count = 0
}
}
} }
libtls { libtls {
@@ -14,6 +14,9 @@ charon-systemd {
} }
} }
plugins { plugins {
eap-ttls {
max_message_count = 0
}
tnc-imc { tnc-imc {
preferred_language = de preferred_language = de
} }
@@ -14,6 +14,7 @@ charon-systemd {
} }
plugins { plugins {
eap-ttls { eap-ttls {
max_message_count = 0
phase2_method = md5 phase2_method = md5
phase2_piggyback = yes phase2_piggyback = yes
phase2_tnc = yes phase2_tnc = yes
@@ -12,8 +12,8 @@ to exchange PA-TNC attributes.
<em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front <em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front
to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an
<em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference <em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference
measurement on all files in the <b>/bin</b> directory. <b>carol</b> is then prompted to measurement on all files in the <b>/usr/sbin</b> directory. <b>carol</b> is then prompted to
measure a couple of individual files and the files in the <b>/bin</b> directory as measure a couple of individual files and the files in the <b>/usr/sbin</b> directory as
well as to get metadata on the <b>/etc/tnc_confg</b> configuration file. well as to get metadata on the <b>/etc/tnc_confg</b> configuration file.
<p/> <p/>
Since the Attestation IMV negotiates a Diffie-Hellman group for TPM-based measurements, Since the Attestation IMV negotiates a Diffie-Hellman group for TPM-based measurements,
@@ -12,6 +12,11 @@ charon-systemd {
pts = 3 pts = 3
} }
} }
plugins {
eap-ttls {
max_message_count = 0
}
}
} }
libtls { libtls {
@@ -13,6 +13,9 @@ charon-systemd {
} }
} }
plugins { plugins {
eap-ttls {
max_message_count = 0
}
tnc-imc { tnc-imc {
preferred_language = de preferred_language = de
} }
@@ -14,6 +14,7 @@ charon-systemd {
} }
plugins { plugins {
eap-ttls { eap-ttls {
max_message_count = 0
phase2_method = md5 phase2_method = md5
phase2_piggyback = yes phase2_piggyback = yes
phase2_tnc = yes phase2_tnc = yes
@@ -12,8 +12,8 @@ defined by <b>RFC 5792 PA-TNC</b>.
<em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front <em>Product Information</em>, <em>String Version</em>, and <em>Device ID</em> up-front
to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an to the Attestation IMV, whereas <b>dave</b> must be prompted by the IMV to do so via an
<em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference <em>Attribute Request</em> PA-TNC attribute. <b>dave</b> is instructed to do a reference
measurement on all files in the <b>/bin</b> directory. <b>carol</b> is then prompted to measurement on all files in the <b>/usr/sbin</b> directory. <b>carol</b> is then prompted to
measure a couple of individual files and the files in the <b>/bin</b> directory as measure a couple of individual files and the files in the <b>/usr/sbin</b> directory as
well as to get metadata on the <b>/etc/tnc_confg</b> configuration file. well as to get metadata on the <b>/etc/tnc_confg</b> configuration file.
<p> <p>
<b>carol</b> passes the health test and <b>dave</b> fails because IP forwarding is <b>carol</b> passes the health test and <b>dave</b> fails because IP forwarding is
@@ -12,6 +12,11 @@ charon-systemd {
pts = 3 pts = 3
} }
} }
plugins {
eap-ttls {
max_message_count = 0
}
}
} }
libtls { libtls {
@@ -13,6 +13,9 @@ charon-systemd {
} }
} }
plugins { plugins {
eap-ttls {
max_message_count = 0
}
tnc-imc { tnc-imc {
preferred_language = de preferred_language = de
} }
@@ -14,6 +14,7 @@ charon-systemd {
} }
plugins { plugins {
eap-ttls { eap-ttls {
max_message_count = 0
phase2_method = md5 phase2_method = md5
phase2_piggyback = yes phase2_piggyback = yes
phase2_tnc = yes phase2_tnc = yes