vtpm: add ordinal for obtaining an EK signature
authorDaniel De Graaf <dgdegra@tycho.nsa.gov>
Mon, 21 Apr 2014 17:23:02 +0000 (13:23 -0400)
committerIan Campbell <ian.campbell@citrix.com>
Wed, 23 Apr 2014 10:57:53 +0000 (11:57 +0100)
commitd4ea6ab10f35f98a15ccc612f2235198bb733412
tree0ef0cc8f10f260e03d743000605f022612ced210
parentc1fe4dcf3f9b2641b668d912d2894e9df9096538
vtpm: add ordinal for obtaining an EK signature

For a vTPM to be useful for remote attestation, proof that the vTPM's EK
was generated and held within a secure vTPM implementation is necessary.
This patch adds an ordinal to the vTPM which will request a quote
providing this evidence from the TPM Manager; it only functions during
the first startup of a given vTPM in order to provide proof that the EK
was freshly generated (and not a key whose private part is available
elsewhere).

Signed-off-by: Daniel De Graaf <dgdegra@tycho.nsa.gov>
Acked-by: Ian Campbell <ian.campbell@citrix.com>
stubdom/Makefile
stubdom/vtpm-parent-sign-ek.patch [new file with mode: 0644]
stubdom/vtpm/vtpm_cmd.c