From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received-SPF: Pass (sender SPF authorized) identity=mailfrom; client-ip=192.55.52.120; helo=mga04.intel.com; envelope-from=chao.b.zhang@intel.com; receiver=edk2-devel@lists.01.org Received: from mga04.intel.com (mga04.intel.com [192.55.52.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ml01.01.org (Postfix) with ESMTPS id 2B75821157421 for ; Tue, 25 Sep 2018 06:44:44 -0700 (PDT) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from fmsmga004.fm.intel.com ([10.253.24.48]) by fmsmga104.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 25 Sep 2018 06:44:44 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.54,302,1534834800"; d="scan'208";a="91748709" Received: from fmsmsx106.amr.corp.intel.com ([10.18.124.204]) by fmsmga004.fm.intel.com with ESMTP; 25 Sep 2018 06:41:48 -0700 Received: from fmsmsx102.amr.corp.intel.com (10.18.124.200) by FMSMSX106.amr.corp.intel.com (10.18.124.204) with Microsoft SMTP Server (TLS) id 14.3.319.2; Tue, 25 Sep 2018 06:41:47 -0700 Received: from shsmsx103.ccr.corp.intel.com (10.239.4.69) by FMSMSX102.amr.corp.intel.com (10.18.124.200) with Microsoft SMTP Server (TLS) id 14.3.319.2; Tue, 25 Sep 2018 06:41:47 -0700 Received: from shsmsx102.ccr.corp.intel.com ([169.254.2.140]) by SHSMSX103.ccr.corp.intel.com ([169.254.4.245]) with mapi id 14.03.0319.002; Tue, 25 Sep 2018 21:41:45 +0800 From: "Zhang, Chao B" To: Jorge Fernandez Monteagudo , "edk2-devel@lists.01.org" Thread-Topic: Tianocore and TPM2 pcr values Thread-Index: AQHUU+rT8A2Fo9tZ6UKOSIY+RzW2uqUA/67g Date: Tue, 25 Sep 2018 13:41:45 +0000 Message-ID: References: In-Reply-To: Accept-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ctpclassification: CTP_NT x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiZmU0OTNlYmItMjkzNi00NzU4LTllMGItNmVlOTE5ZjM3ODI2IiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX05UIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE3LjEwLjE4MDQuNDkiLCJUcnVzdGVkTGFiZWxIYXNoIjoid21GUFJCQ3YzRjJDdXJpb3VQQnZMVHJNVzBwSER1TWN6ZTZZRnlBQ0IyRElXdUI5ZE9cL0s0ZUtMQytQdEYxd1AifQ== dlp-product: dlpe-windows dlp-version: 11.0.400.15 dlp-reaction: no-action x-originating-ip: [10.239.127.40] MIME-Version: 1.0 Subject: Re: Tianocore and TPM2 pcr values X-BeenThere: edk2-devel@lists.01.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: EDK II Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Sep 2018 13:44:45 -0000 Content-Language: en-US Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi Jorge: PCR 0 should change if you use different core boot payload + UEFI. So = your case seems to be an issue. Can you provide more detailed info?=20 -----Original Message----- From: edk2-devel [mailto:edk2-devel-bounces@lists.01.org] On Behalf Of Jorg= e Fernandez Monteagudo Sent: Monday, September 24, 2018 5:57 PM To: edk2-devel@lists.01.org Subject: [edk2] Tianocore and TPM2 pcr values Hi all, This is my first message in this list. I'm using tianocore as a payload for= a Coreboot in order to boot a custom board I'm working on it. Finally I've been able to enable the= TPM2 support in coreboot and in tianocore but I have some questions regarding the values I'= m seeing in the PCRs. I'm using Tianocore master branch as is selected by coreboot menuconfig and= x64 architecture. Once the system is running I can read the PCRs and, if I'm not wrong, PCRs = 0 to 7 are handled by the Tianocore/Coreboot. I've flashed a coreboot+tianocore in release mod= e and a coreboot+ tianocore in debug mode and the PCRs are the same. Is it ok? I thought that= any change in the coreboot.rom will made the PCR values to change... pcr0: 3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 pcr1: a3a3552caa68c6d9db64bf1ed4dca08080f99b59f1b26debc9abefa59ee8ca28 pcr2: 3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 pcr3: 3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 pcr4: 74a35102770e65ab94b35135a4bf54c411134ae8059e03df41060a33f573871f pcr5: dfa65561584cb8604b1675c869f3341d0c99c642ce9d91353380361126235ad8 pcr6: 3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 pcr7: b5710bf57d25623e4019027da116821fa99f5c81e9e38b87671cc574f9281439 Another test I've done is using the Tianocore stable branch as selected by = coreboot (STABLE_COMMIT_ID=3D315d9d08fd77db1024ccc5307823da8aaed85e2f) and I get the= same values from release and build coreboot.roms except that PCR1 has the = same value as PCR0, 2, 3 and 6, it seems it's not used in this version. Is this the expected behavior? Thanks! Jorge _______________________________________________ edk2-devel mailing list edk2-devel@lists.01.org https://lists.01.org/mailman/listinfo/edk2-devel