Both D and T flags required to be set for PTS Component Measurement

DH Finish is sent only when D flag is set in TPM_INIT phase
This commit is contained in:
Sansar Choinyambuu
2011-11-28 14:39:52 +01:00
committed by Andreas Steffen
parent 6c5c5b6a2e
commit cb83fb3b72
@@ -42,6 +42,8 @@ bool imv_attestation_build(pa_tnc_msg_t *msg,
handshake_state = attestation_state->get_handshake_state(attestation_state); handshake_state = attestation_state->get_handshake_state(attestation_state);
pts = attestation_state->get_pts(attestation_state); pts = attestation_state->get_pts(attestation_state);
/* D-H attributes are redundant */
/* when D-H Nonce Exchange is not selected on IMC side */
if (handshake_state == IMV_ATTESTATION_STATE_NONCE_REQ && if (handshake_state == IMV_ATTESTATION_STATE_NONCE_REQ &&
!(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_D)) !(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_D))
{ {
@@ -49,6 +51,8 @@ bool imv_attestation_build(pa_tnc_msg_t *msg,
"advancing to TPM Initialization phase"); "advancing to TPM Initialization phase");
handshake_state = IMV_ATTESTATION_STATE_TPM_INIT; handshake_state = IMV_ATTESTATION_STATE_TPM_INIT;
} }
/* TPM Version Info, AIK attributes are redundant */
/* when TPM is not available on IMC side */
if (handshake_state == IMV_ATTESTATION_STATE_TPM_INIT && if (handshake_state == IMV_ATTESTATION_STATE_TPM_INIT &&
!(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_T)) !(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_T))
{ {
@@ -56,8 +60,11 @@ bool imv_attestation_build(pa_tnc_msg_t *msg,
"advancing to File Measurement phase"); "advancing to File Measurement phase");
handshake_state = IMV_ATTESTATION_STATE_MEAS; handshake_state = IMV_ATTESTATION_STATE_MEAS;
} }
/* Component Measurement cannot be done without D-H Nonce Exchange */
/* or TPM on IMC side */
if (handshake_state == IMV_ATTESTATION_STATE_COMP_EVID && if (handshake_state == IMV_ATTESTATION_STATE_COMP_EVID &&
!(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_T)) (!(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_T) ||
!(pts->get_proto_caps(pts) & PTS_PROTO_CAPS_D)) )
{ {
DBG1(DBG_IMV, "PTS-IMC has not got TPM available," DBG1(DBG_IMV, "PTS-IMC has not got TPM available,"
"skipping Component Measurement phase"); "skipping Component Measurement phase");
@@ -107,13 +114,16 @@ bool imv_attestation_build(pa_tnc_msg_t *msg,
pts_meas_algorithms_t selected_algorithm; pts_meas_algorithms_t selected_algorithm;
chunk_t initiator_value, initiator_nonce; chunk_t initiator_value, initiator_nonce;
/* Send DH nonce finish attribute */ if ((pts->get_proto_caps(pts) & PTS_PROTO_CAPS_D))
selected_algorithm = pts->get_meas_algorithm(pts); {
pts->get_my_public_value(pts, &initiator_value, &initiator_nonce); /* Send DH nonce finish attribute */
attr = tcg_pts_attr_dh_nonce_finish_create(selected_algorithm, selected_algorithm = pts->get_meas_algorithm(pts);
initiator_value, initiator_nonce); pts->get_my_public_value(pts, &initiator_value, &initiator_nonce);
attr->set_noskip_flag(attr, TRUE); attr = tcg_pts_attr_dh_nonce_finish_create(selected_algorithm,
msg->add_attribute(msg, attr); initiator_value, initiator_nonce);
attr->set_noskip_flag(attr, TRUE);
msg->add_attribute(msg, attr);
}
/* Send Get TPM Version attribute */ /* Send Get TPM Version attribute */
attr = tcg_pts_attr_get_tpm_version_info_create(); attr = tcg_pts_attr_get_tpm_version_info_create();