Re: boot-time vtpm helper (was "Re: <void>")

From: Stefan Berger
Date: Thu Aug 03 2023 - 08:47:07 EST

On 8/3/23 05:06, Jarkko Sakkinen wrote:
On Thu Aug 3, 2023 at 11:25 AM EEST, Jarkko Sakkinen wrote:

I have a working PoC for boot-time initialization of vtpm inside
tpm_vtpm_proxy. ATM, it uses the Linux firmware interface to load a ELF
binary for the vtpm, and delivers a communication end for the helper

It is a great feature with the current narrow scope for continuous
integration. Obviously the scope could be later on extended to e.g.

Since VMs with vTPMs exist, which CI/CD environment would one use this in?

Where does the binary for the vtpm live when it's loaded with the firmware interface?

from unencrypted plain text to a vTPM living inside SGX enclave.

I would run swtpm inside an SGX enclave using Gramine.


I could send an RFC of this, if there is wider interest for the

