enforce pcr4

This commit is contained in:
Thomas Tendyck 2022-09-08 17:09:49 +02:00 committed by Thomas Tendyck
parent ef26917c5e
commit a85777fd02
3 changed files with 7 additions and 5 deletions

View file

@ -147,7 +147,7 @@ The latter means that value can be generated offline and compared to the one in
| 7 | Secure Boot State | Azure, Constellation Bootloader | No |
| 8 | Kernel command line, GRUB config | Constellation Bootloader | Yes |
| 9 | Kernel, initramfs | Constellation Bootloader | Yes |
| 10 | Reserved | - | Yes |
| 10 | Reserved | - | No |
| 11 | Reserved | Constellation Bootstrapper | Yes |
| 12 | ClusterID | Constellation Bootstrapper | Yes |
| 13–23 | Unused | - | - |
@ -177,7 +177,7 @@ The latter means that value can be generated offline and compared to the one in
| 7 | GCP Secure Boot Policy | GCP, Constellation Bootloader | No |
| 8 | Kernel command line, GRUB config | Constellation Bootloader | Yes |
| 9 | Kernel, initramfs | Constellation Bootloader | Yes |
| 10 | Reserved | Constellation Bootstrapper | Yes |
| 10 | Reserved | - | No |
| 11 | Reserved | Constellation Bootstrapper | Yes |
| 12 | ClusterID | Constellation Bootstrapper | Yes |
| 13–23 | Unused |- | - |
@ -233,5 +233,5 @@ flowchart LR
B[CLI]-- "contains" -->D["Public Key"]
A[Edgeless]-- "signs" -->E["Runtime measurements"]
D["Public Key"]-- "verifies" -->E["Runtime measurements"]
E["Runtime measurements"]-- "verify" -->F["Constellation cluster"]
E["Runtime measurements"]-- "verify" -->F["Constellation cluster"]
```