From: "Daniel P. Smith" <dpsmith@apertussolutions.com>
To: Thomas Gleixner <tglx@linutronix.de>,
"Eric W. Biederman" <ebiederm@xmission.com>,
Eric Biggers <ebiggers@kernel.org>
Cc: Ross Philipson <ross.philipson@oracle.com>,
linux-kernel@vger.kernel.org, x86@kernel.org,
linux-integrity@vger.kernel.org, linux-doc@vger.kernel.org,
linux-crypto@vger.kernel.org, kexec@lists.infradead.org,
linux-efi@vger.kernel.org, iommu@lists.linux-foundation.org,
mingo@redhat.com, bp@alien8.de, hpa@zytor.com,
dave.hansen@linux.intel.com, ardb@kernel.org,
mjg59@srcf.ucam.org, James.Bottomley@hansenpartnership.com,
peterhuewe@gmx.de, jarkko@kernel.org, jgg@ziepe.ca,
luto@amacapital.net, nivedita@alum.mit.edu,
herbert@gondor.apana.org.au, davem@davemloft.net, corbet@lwn.net,
dwmw2@infradead.org, baolu.lu@linux.intel.com,
kanth.ghatraju@oracle.com, andrew.cooper3@citrix.com,
trenchboot-devel@googlegroups.com
Subject: Re: [PATCH v9 06/19] x86: Add early SHA-1 support for Secure Launch early measurements
Date: Thu, 22 Aug 2024 14:29:48 -0400 [thread overview]
Message-ID: <281c3bb3-13f6-47a2-9a9a-134e397bf686@apertussolutions.com> (raw)
In-Reply-To: <87ttflli09.ffs@tglx>
On 8/15/24 15:10, Thomas Gleixner wrote:
> On Thu, Aug 15 2024 at 13:38, Daniel P. Smith wrote:
>> On 5/31/24 09:54, Eric W. Biederman wrote:
>>> Eric Biggers <ebiggers@kernel.org> writes:
>>>> That paragraph is also phrased as a hypothetical, "Even if we'd prefer to use
>>>> SHA-256-only". That implies that you do not, in fact, prefer SHA-256 only. Is
>>>> that the case? Sure, maybe there are situations where you *have* to use SHA-1,
>>>> but why would you not at least *prefer* SHA-256?
>>>
>>> Yes. Please prefer to use SHA-256.
>>>
>>> Have you considered implementing I think it is SHA1-DC (as git has) that
>>> is compatible with SHA1 but blocks the known class of attacks where
>>> sha1 is actively broken at this point?
>>
>> We are using the kernel's implementation, addressing what the kernel
>> provides is beyond our efforts. Perhaps someone who is interested in
>> improving the kernel's SHA1 could submit a patch implementing/replacing
>> it with SHA1-DC, as I am sure the maintainers would welcome the help.
>
> Well, someone who is interested to get his "secure" code merged should
> have a vested interested to have a non-broken SHA1 implementation if
> there is a sensible requirement to use SHA1 in that new "secure" code,
> no?
>
> Just for the record. The related maintainers can rightfully decide to
> reject known broken "secure" code on a purely technical argument.
>
> Thanks,
>
> tglx
>
There is one simple question, does allowing the Secure Launch code to
record SHA1 measurements make the system insecure, and the answer is
absolutely not.
The role of the Secure Launch code base in the context of the larger
launch process is to function as observer. Within this role, its only
responsibility is continuing the trust chain(s) that were started by the
CPU/Hardware. It does so by measuring the components and configuration
it is responsible for loading and applying, i.e. in TCG parlance, it is
continuing the construction of the transitive trust for the system. In
this aspect, the only degradation of security that can affect the
kernel's role is whether all the necessary entities are safely measured
and not what algorithms are used.
If the system integrator, whether that be the OEM, your employer, the
distro maintainer, the system administrator, or the end user, configures
the DL preamble to only use SHA1 or used older hardware that has a
TPM1.2, then they are accepting the risk it creates in their solution.
In fact, a greater threat to the security of the launch is the
misconfiguration of the IOMMU, which risks the kernel's ability to
safely make measurements, as compared to the use of SHA1. Yet it was
insisted in past reviews that we allow the user to specify an incorrect
IOMMU policy.
In the end, the "security" of an RTM solution is how and what
measurements are used to assess the health of a system. Thus bringing it
back to the opening question, if SHA1 measurements are made but not
used, i.e. the attestation enforcement only uses SHA2, then it has zero
impact on the security of the system.
Another fact to consider is that the current Intel's TXT MLE
specification dictates SHA1 as a valid configuration. Secure Launch's
use of SHA1 is therefore to comply with Intel's specification for TXT.
And like the IOMMU situation, having the option available allows the
user to determine how they ultimately want to integrate Secure Launch
into their integrity management. And because Secure Launch will only
attempt SHA1 if it was in the TXT configuration, when either Intel
removes SHA1 from the MLE specification or firmware manufactures begin
disabling the SHA1 banks, this will obviously mean that Secure Launch
will not produce SHA1 measurements.
On a side note, with my remote attestation hat on, the SHA1 measurements
can in fact be extremely useful. If an attestation was made containing
both SHA1 and SHA2 chains, and the SHA1 of an event was correct but the
SHA2 was not, either a natural collision happened or someone maliciously
caused a collision. The former has an extremely low probability, while
the latter is highly probable.
Thus, with this information alone, it is possible to make the reasonable
determination the device is compromised. Whereas if both hashes are
mismatched, without any additional information it is equally probable of
either misconfiguration or compromise. And to state the obvious, with
only SHA2, further information is needed to distinguish between
misconfiguration and compromise.
V/r,
Daniel P. Smith
next prev parent reply other threads:[~2024-08-22 18:31 UTC|newest]
Thread overview: 116+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-05-31 1:03 [PATCH v9 00/19] x86: Trenchboot secure dynamic launch Linux kernel support Ross Philipson
2024-05-31 1:03 ` [PATCH v9 01/19] x86/boot: Place kernel_info at a fixed offset Ross Philipson
2024-06-04 18:18 ` Jarkko Sakkinen
2024-06-04 20:28 ` ross.philipson
2024-05-31 1:03 ` [PATCH v9 02/19] Documentation/x86: Secure Launch kernel documentation Ross Philipson
2024-05-31 1:03 ` [PATCH v9 03/19] x86: Secure Launch Kconfig Ross Philipson
2024-05-31 1:03 ` [PATCH v9 04/19] x86: Secure Launch Resource Table header file Ross Philipson
2024-06-04 18:21 ` Jarkko Sakkinen
2024-06-04 20:31 ` ross.philipson
2024-06-04 22:36 ` Jarkko Sakkinen
2024-06-04 23:00 ` ross.philipson
2024-06-05 0:22 ` Jarkko Sakkinen
2024-06-05 0:27 ` Jarkko Sakkinen
2024-06-05 2:33 ` ross.philipson
2024-06-05 4:04 ` Jarkko Sakkinen
2024-06-05 19:03 ` ross.philipson
2024-06-06 6:02 ` Jarkko Sakkinen
2024-06-06 16:49 ` ross.philipson
2024-06-20 0:18 ` Jarkko Sakkinen
2024-06-20 16:55 ` ross.philipson
2024-05-31 1:03 ` [PATCH v9 05/19] x86: Secure Launch main " Ross Philipson
2024-06-04 18:24 ` Jarkko Sakkinen
2024-06-04 20:52 ` ross.philipson
2024-05-31 1:03 ` [PATCH v9 06/19] x86: Add early SHA-1 support for Secure Launch early measurements Ross Philipson
2024-05-31 2:16 ` Eric Biggers
2024-05-31 13:54 ` Eric W. Biederman
2024-08-15 17:38 ` Daniel P. Smith
2024-08-15 19:10 ` Thomas Gleixner
2024-08-16 10:42 ` Jarkko Sakkinen
2024-08-16 11:01 ` Andrew Cooper
2024-08-16 11:22 ` Jarkko Sakkinen
2024-08-16 18:41 ` Matthew Garrett
2024-08-19 18:05 ` Jarkko Sakkinen
2024-08-19 18:24 ` Matthew Garrett
2024-08-20 15:26 ` Jarkko Sakkinen
2024-08-22 18:29 ` Daniel P. Smith [this message]
2026-02-20 15:35 ` Ard Biesheuvel
2026-02-23 23:08 ` Andrew Cooper
2026-02-24 8:25 ` Ard Biesheuvel
2024-08-29 3:17 ` Andy Lutomirski
2024-08-29 3:25 ` Matthew Garrett
2024-08-29 17:26 ` Andy Lutomirski
2024-09-05 1:01 ` Daniel P. Smith
2024-09-13 0:34 ` Daniel P. Smith
2024-09-14 3:57 ` Andy Lutomirski
2024-09-21 18:36 ` Daniel P. Smith
2024-09-21 22:40 ` Andy Lutomirski
2024-11-02 14:53 ` Daniel P. Smith
2024-11-02 16:04 ` James Bottomley
2024-11-15 1:17 ` Daniel P. Smith
2024-11-18 18:43 ` Andy Lutomirski
2024-11-18 18:50 ` Andy Lutomirski
2024-11-18 19:12 ` James Bottomley
2024-11-18 20:02 ` Andy Lutomirski
2024-11-21 20:11 ` ross.philipson
2024-11-21 20:54 ` Andy Lutomirski
2024-11-21 22:42 ` Andy Lutomirski
2024-11-22 23:37 ` ross.philipson
2024-12-12 19:56 ` Daniel P. Smith
2024-12-12 22:30 ` Andy Lutomirski
2024-12-14 2:56 ` Daniel P. Smith
2024-05-31 16:18 ` ross.philipson
2024-08-27 18:14 ` Eric Biggers
2024-08-28 20:14 ` ross.philipson
2024-08-28 23:13 ` Eric Biggers
2024-06-04 18:52 ` Jarkko Sakkinen
2024-06-04 21:02 ` ross.philipson
2024-06-04 22:40 ` Jarkko Sakkinen
2024-05-31 1:03 ` [PATCH v9 07/19] x86: Add early SHA-256 " Ross Philipson
2024-05-31 1:03 ` [PATCH v9 08/19] x86: Secure Launch kernel early boot stub Ross Philipson
2024-05-31 11:00 ` Ard Biesheuvel
2024-05-31 13:33 ` Ard Biesheuvel
2024-05-31 14:04 ` Ard Biesheuvel
2024-05-31 16:13 ` Ard Biesheuvel
2024-06-04 17:31 ` ross.philipson
2024-06-04 17:24 ` ross.philipson
2024-06-04 17:27 ` Ard Biesheuvel
2024-06-04 17:33 ` ross.philipson
2024-06-04 20:54 ` Ard Biesheuvel
2024-06-04 21:12 ` ross.philipson
2024-06-04 17:14 ` ross.philipson
2024-06-04 19:56 ` Jarkko Sakkinen
2024-06-04 21:09 ` ross.philipson
2024-06-04 22:43 ` Jarkko Sakkinen
2024-05-31 1:03 ` [PATCH v9 09/19] x86: Secure Launch kernel late " Ross Philipson
2024-06-04 19:58 ` Jarkko Sakkinen
2024-06-04 21:16 ` ross.philipson
2024-06-04 22:45 ` Jarkko Sakkinen
2024-06-04 19:59 ` Jarkko Sakkinen
2024-06-04 21:17 ` ross.philipson
2024-08-12 19:02 ` ross.philipson
2024-08-15 18:35 ` Jarkko Sakkinen
2024-05-31 1:03 ` [PATCH v9 10/19] x86: Secure Launch SMP bringup support Ross Philipson
2024-06-04 20:05 ` Jarkko Sakkinen
2024-06-04 21:47 ` ross.philipson
2024-06-04 22:46 ` Jarkko Sakkinen
2024-05-31 1:03 ` [PATCH v9 11/19] kexec: Secure Launch kexec SEXIT support Ross Philipson
2024-05-31 1:03 ` [PATCH v9 12/19] reboot: Secure Launch SEXIT support on reboot paths Ross Philipson
2024-05-31 1:03 ` [PATCH v9 13/19] tpm: Protect against locality counter underflow Ross Philipson
2024-06-04 20:12 ` Jarkko Sakkinen
2024-08-15 18:52 ` Daniel P. Smith
2024-05-31 1:03 ` [PATCH v9 14/19] tpm: Ensure tpm is in known state at startup Ross Philipson
2024-06-04 20:14 ` Jarkko Sakkinen
2024-08-15 19:24 ` Daniel P. Smith
2024-05-31 1:03 ` [PATCH v9 15/19] tpm: Make locality requests return consistent values Ross Philipson
2024-05-31 1:03 ` [PATCH v9 16/19] tpm: Add ability to set the preferred locality the TPM chip uses Ross Philipson
2024-06-04 20:27 ` Jarkko Sakkinen
2024-06-04 22:14 ` ross.philipson
2024-06-04 22:50 ` Jarkko Sakkinen
2024-06-04 23:04 ` ross.philipson
2024-05-31 1:03 ` [PATCH v9 17/19] tpm: Add sysfs interface to allow setting and querying the preferred locality Ross Philipson
2024-06-04 20:27 ` Jarkko Sakkinen
2024-05-31 1:03 ` [PATCH v9 18/19] x86: Secure Launch late initcall platform module Ross Philipson
2024-05-31 1:03 ` [PATCH v9 19/19] x86: EFI stub DRTM launch support for Secure Launch Ross Philipson
2024-05-31 11:09 ` Ard Biesheuvel
2024-06-04 17:22 ` ross.philipson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=281c3bb3-13f6-47a2-9a9a-134e397bf686@apertussolutions.com \
--to=dpsmith@apertussolutions.com \
--cc=James.Bottomley@hansenpartnership.com \
--cc=andrew.cooper3@citrix.com \
--cc=ardb@kernel.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=dwmw2@infradead.org \
--cc=ebiederm@xmission.com \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux-foundation.org \
--cc=jarkko@kernel.org \
--cc=jgg@ziepe.ca \
--cc=kanth.ghatraju@oracle.com \
--cc=kexec@lists.infradead.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=mingo@redhat.com \
--cc=mjg59@srcf.ucam.org \
--cc=nivedita@alum.mit.edu \
--cc=peterhuewe@gmx.de \
--cc=ross.philipson@oracle.com \
--cc=tglx@linutronix.de \
--cc=trenchboot-devel@googlegroups.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®