haraldh · GitHub

Merged

Merged

Conversation

The UEFI BIOS already hashes the contents of the loaded image, so the
initrd and the command line of the binary are recorded.
Because manually added LoadOptions are not taken into account, these
should be recorded also.
This patch logs and extends a TPM PCR register with the LoadOptions.
This feature can be enabled with configure --enable-tpm
The PCR register index can be specified with
configure --with-tpm-pcrindex=<NUM>

Closed

poettering added a commit that referenced this pull request

Feb 11, 2016
sd-boot: put hashed kernel command line in a PCR of the TPM

@poettering

Closed

Read the original on github.com ↗