Add WithPlatformConfigProfile() (for PCR1)
- Dominant language
- Go
- Stars
- 23
- Forks
- 29
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 2
Description
If PCR7 isn't supported for some reason, eg, because secure boot is disabled or the device is not in deployed mode, then we should be able to fall back to a safe profile that includes PCRs 1, 2, 3, 4 and 5. PCR 2 and 4 are for binding to all code that's loaded outside of the platform firmware.
It should also be possible to optionally bind to PCR1 using the `PCRProfileOptionsFlags`.
PCR1 is to bind to all of the platform firmware's configuration - currently, changes to security-sensitive settings such as enabling a debugger or disabling DMA remapping change the value of PCR7 by adding extra `EVI_EFI_ACTION` events.
PCR3 contains any configuration related to UEFI drivers that are not part of the platform firmware.
PCR5 contains the GPT of the IBL and can be used for any bootloader configuration, and support for this will be tracked in a separate issue.
To support this, the efi package needs a new `WithPlatformConfigProfile` API that will support PCR1.
Most events for PCR1 will be copied from the log to the profile, with the exception of:
- BootOrder and BootXXXX global variable `EV_EFI_VARIABLE_BOOT` and `EV_EFI_VARIABLE_BOOT2` events, as these can be computed in order to support updating these variables.
- `EV_ACTION` events with the data "Entering ROM Based Setup" - profile generation should fail in this case and the pre-install checks should catch this and advise a reboot if PCR1 is required.
- `EV_ACTION` events with the data "Chassis Intrusion" - profile generation should fail in this case and the pre-install checks should catch this and advise this condition is cleared before continuing if PCR1 is required.
To support updates to BootOrder and BootXXXX variables, additional options will be required for `AddPCRProfile`. Where multiple variables are updated in a single transaction, each individual variable update needs to go into a new PCR policy branch in the same way that signature database updates do. PCR policies must be updated before and after each transaction to update these variables.
Contributor guide
Assessment
This issue has not been assessed yet.