Skip to content

feat: support nv pcr policy#12

Draft
gibix wants to merge 1 commit intomainfrom
tpm/pcr
Draft

feat: support nv pcr policy#12
gibix wants to merge 1 commit intomainfrom
tpm/pcr

Conversation

@gibix
Copy link
Member

@gibix gibix commented Jan 16, 2026

To seal/unseal TPM keys we need to attest that we are on a trusted system,

this means sealing/unsealing based on the values of the following TPM PCR registes:

  • PCR#7: state of Secure Boot (breaks whenever secure boot is
  • PCR#12: stboot OS Detail Measurements (breaks whenever a different OS is loaded)
  • PCR#13: stboot OS Authority Measurements (breaks whenever a different trust policy or certificate is used)

https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/
https://docs.system-transparency.org/st-1.3.0/archive/ra/stboot-measurements/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant