eLxr Trusted Platform Module Setup and Usage Guide¶
Contents:
Overview¶
A Trusted Platform Module (TPM) is a hardware or firmware security component that provides a hardware root of trust. It stores cryptographic keys and records integrity measurements in Platform Configuration Registers (PCRs), which can be used to verify firmware, boot, and runtime integrity and to support remote attestation.
This guide describes how to set up and use TPM 2.0 support in the eLxr kernel for the bianca release line.
For background on the TPM 2.0 standard and its usage, see the following external resources:
What Is Included¶
TPM 2.0 core drivers, including tpm, tpm_tis, tpm_tis_spi, tpm_tis_i2c, tpm_crb
Integrity Measurement Architecture (IMA)
IMA runtime measurement policy for remote attestation
tpm2-tools userspace integration
Benefits¶
Boot integrity: Firmware and boot-loader measurements are extended into TPM PCRs, creating an auditable chain of trust.
Runtime integrity: IMA measures files as they are executed or loaded, storing hashes in the kernel and extending PCR 10.
Remote attestation: A verifier can request a TPM quote over PCRs, including PCR 10 for IMA, and compare it against an expected value.
Kernel Configuration¶
The eLxr bianca kernel enables the following TPM/IMA options by default:
CONFIG_TCG_TPM=m
CONFIG_TCG_TIS=m
CONFIG_TCG_TIS_SPI=m
CONFIG_TCG_TIS_I2C=m
CONFIG_TCG_CRB=m
CONFIG_IMA=y
CONFIG_IMA_MEASURE_PCR_IDX=10
CONFIG_IMA_APPRAISE_BOOTPARAM=y
CONFIG_IMA_APPRAISE_MODSIG=y
A default IMA measurement policy is shipped with the image package at:
/etc/ima/ima-policy-remote-attestation
The policy measures executables, memory-mapped executables, kernel modules, firmware, kexec kernels, and policy changes.