[PATCH 00/22] KEYS: Support TPM-wrapped key and crypto ops

Denis Kenzior denkenz at gmail.com
Tue Sep 18 17:00:49 UTC 2018


Hi David,

On 09/18/2018 11:55 AM, David Howells wrote:
> Denis Kenzior <denkenz at gmail.com> wrote:
> 
>> In theory the PEM file already contains the type of the certificate, at least
>> at a high level.  E.g. private, public, tpm.  So if we accept PEM files
>> directly that could be potentially a faster way of determining the parser to
>> use and would still work with keyctl update/instantiate, right?
> 
> Yes.  It shouldn't be much code, either.  You still have to check for X.509
> DER since the kernel currently supports that.

For reasons of backward compatibility, correct?  The kernel also has 
mscode.asn1 which we would need to support as well.  Since we can't 
break compatibility then perhaps this doesn't buy us a whole lot in the end.

Regards,
-Denis



More information about the Linux-security-module-archive mailing list