Implemented TPM_Quote2 on imc and constructing TPM_Quote_Info2 on imv
This commit is contained in:
committed by
Andreas Steffen
parent
868c24b2a4
commit
f6aab3cd1e
@@ -60,7 +60,7 @@ static u_int8_t* string_to_bytearray(char *str_value)
|
||||
for (i = 0; i < strlen(str_value)/2; i++)
|
||||
{
|
||||
char c1, c2;
|
||||
u_int8_t d1, d2;
|
||||
u_int8_t d1 = 0, d2 = 0;
|
||||
|
||||
c1 = str_value[i*2];
|
||||
c2 = str_value[i*2 + 1];
|
||||
@@ -547,6 +547,7 @@ bool imc_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
chunk_t pcr_composite, quote_signature;
|
||||
u_int32_t num_of_evidences, i = 0;
|
||||
u_int32_t *pcrs;
|
||||
bool use_quote2;
|
||||
|
||||
/* Send buffered Simple Component Evidences */
|
||||
num_of_evidences = evidences->get_count(evidences);
|
||||
@@ -568,9 +569,13 @@ bool imc_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
/* Send Simple Compoenent Evidence */
|
||||
attr_list->insert_last(attr_list, attr);
|
||||
}
|
||||
|
||||
use_quote2 = (lib->settings->get_int(lib->settings,
|
||||
"libimcv.plugins.imc-attestation.quote_version", 1) == 1) ?
|
||||
FALSE : TRUE;
|
||||
|
||||
/* Quote */
|
||||
if (!pts->quote_tpm(pts, pcrs, num_of_evidences,
|
||||
if (!pts->quote_tpm(pts, use_quote2, pcrs, num_of_evidences,
|
||||
&pcr_composite, "e_signature))
|
||||
{
|
||||
DBG1(DBG_IMC, "error occured during TPM quote operation");
|
||||
@@ -580,7 +585,8 @@ bool imc_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
}
|
||||
|
||||
/* Send Simple Evidence Final attribute */
|
||||
flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO;
|
||||
flags = use_quote2 ? PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2:
|
||||
PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO;
|
||||
composite_algorithm |= PTS_MEAS_ALGO_SHA1;
|
||||
|
||||
attr = tcg_pts_attr_simple_evid_final_create(FALSE, flags,
|
||||
|
||||
@@ -281,7 +281,9 @@ bool imv_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
chunk_t pcr_comp;
|
||||
chunk_t tpm_quote_sign;
|
||||
chunk_t evid_sign;
|
||||
bool evid_signature_included;
|
||||
bool evid_signature_included = FALSE, use_quote2 = FALSE,
|
||||
ver_info_included = FALSE;
|
||||
chunk_t pcr_composite, quote_info;
|
||||
|
||||
attr_cast = (tcg_pts_attr_simple_evid_final_t*)attr;
|
||||
evid_signature_included = attr_cast->is_evid_sign_included(attr_cast);
|
||||
@@ -293,16 +295,18 @@ bool imv_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
*/
|
||||
composite_algorithm = attr_cast->get_comp_hash_algorithm(attr_cast);
|
||||
|
||||
if ((flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2) ||
|
||||
(flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER))
|
||||
if (flags != PTS_SIMPLE_EVID_FINAL_FLAG_NO)
|
||||
{
|
||||
DBG1(DBG_IMV, "This version of Attestation IMV can not handle"
|
||||
" TPM Quote Info2 structure");
|
||||
break;
|
||||
}
|
||||
if (flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO)
|
||||
{
|
||||
chunk_t pcr_composite, quote_info;
|
||||
if ((flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2) ||
|
||||
(flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER))
|
||||
{
|
||||
use_quote2 = TRUE;
|
||||
}
|
||||
if (flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER)
|
||||
{
|
||||
ver_info_included = TRUE;
|
||||
}
|
||||
|
||||
pcr_comp = attr_cast->get_pcr_comp(attr_cast);
|
||||
tpm_quote_sign = attr_cast->get_tpm_quote_sign(attr_cast);
|
||||
|
||||
@@ -313,15 +317,15 @@ bool imv_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
DBG1(DBG_IMV, "Either PCR Composite or Quote Signature missing");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* Construct PCR Composite and TPM Quote Info structures*/
|
||||
if (!pts->get_quote_info(pts, composite_algorithm,
|
||||
&pcr_composite, "e_info))
|
||||
|
||||
/* Construct PCR Composite and TPM Quote Info structures */
|
||||
if (!pts->get_quote_info(pts, use_quote2, ver_info_included,
|
||||
composite_algorithm, &pcr_composite, "e_info))
|
||||
{
|
||||
DBG1(DBG_IMV, "unable to contruct TPM Quote Info");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
|
||||
/* Check calculated PCR composite matches with received */
|
||||
if (!chunk_equals(pcr_comp, pcr_composite))
|
||||
{
|
||||
@@ -333,18 +337,18 @@ bool imv_attestation_process(pa_tnc_attr_t *attr, linked_list_t *attr_list,
|
||||
}
|
||||
DBG2(DBG_IMV, "received PCR Composite matches with constructed");
|
||||
chunk_clear(&pcr_composite);
|
||||
|
||||
|
||||
if (!pts->verify_quote_signature(pts, quote_info, tpm_quote_sign))
|
||||
{
|
||||
chunk_clear("e_info);
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
|
||||
DBG2(DBG_IMV, "signature verification succeeded for "
|
||||
"TPM Quote Info");
|
||||
chunk_clear("e_info);
|
||||
}
|
||||
|
||||
|
||||
if (evid_signature_included)
|
||||
{
|
||||
/** TODO: What to do with Evidence Signature */
|
||||
|
||||
Reference in New Issue
Block a user