[51083] in cryptography@c2.net mail archive
RE: TPM & disk crypto
daemon@ATHENA.MIT.EDU (Kuehn, Ulrich)
Mon Oct 9 08:12:47 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 9 Oct 2006 10:34:03 +0200
in-reply-to: <1160085109.4937.21.camel@localhost.localdomain>
From: "Kuehn, Ulrich" <Ulrich.Kuehn@telekom.de>
To: <erik@debian.franken.de>, <solinym@gmail.com>
Cc: <cryptography@metzdowd.com>
=20
> From: Erik Tews [mailto:erik@debian.franken.de]=20
> Sent: Donnerstag, 5. Oktober 2006 23:52
>=20
[...]
>=20
> Later, you can remotely query your system and get a report=20
> what has been bootet on your system. You can do this query=20
> using a java application and tpm4java.
>=20
However, this is the big problem with the TPM according to the TCG spec. =
While you can remotely verify that the system came up according to what =
you installed there, you have no means to force it to either come up the =
way you want, or to be in a clear error state. That is the huge =
difference between the verifiable booting the TPM provides and secure =
booting, which would run only predetermined software.
I assume that the TCG chose not to implement the latter due to fear of =
public bashing...
Ulrich
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com