Skip to content

Conversation

@sjg20
Copy link
Collaborator

@sjg20 sjg20 commented Nov 26, 2025

Add PCR-prediction nodes to allow storing expected TPM PCR values in configurations, enabling TPM policy binding where secrets sealed to expected PCR values can only be unsealed when the correct images are loaded.

Use the existing signature-node structure to sign the PCR predictions for remote attestation, and document the measured boot algorithm specifying the order in which images are measured: kernel, ramdisk, loadables, fdt (with overlays), and cmdline.

Co-developed-by: Claude [email protected]

Add PCR-prediction nodes to allow storing expected TPM PCR values in
configurations, enabling TPM policy binding where secrets sealed to
expected PCR values can only be unsealed when the correct images are
loaded.

Use the existing signature-node structure to sign the PCR predictions
for remote attestation, and document the measured boot algorithm
specifying the order in which images are measured: kernel, ramdisk,
loadables, fdt (with overlays), and cmdline.

Co-developed-by: Claude <[email protected]>
Signed-off-by: Simon Glass <[email protected]>
@netlify
Copy link

netlify bot commented Nov 26, 2025

Deploy Preview for fluffy-chebakia-3fa329 ready!

Name Link
🔨 Latest commit e14165a
🔍 Latest deploy log https://app.netlify.com/projects/fluffy-chebakia-3fa329/deploys/692760e8ddca0a000878a44d
😎 Deploy Preview https://deploy-preview-33--fluffy-chebakia-3fa329.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants