WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xense-devel

RE: [Xense-devel] Vtpm_manager getting TPM_NOSPACE

To: "Scarlata, Vincent R" <vincent.r.scarlata@xxxxxxxxx>, <xense-devel@xxxxxxxxxxxxxxxxxxx>
Subject: RE: [Xense-devel] Vtpm_manager getting TPM_NOSPACE
From: "Osborn, Justin D." <Justin.Osborn@xxxxxxxxxx>
Date: Wed, 6 Dec 2006 13:41:59 -0500
Delivery-date: Wed, 06 Dec 2006 10:41:54 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <D936D925018D154694D8A362EEB08920E2E11F@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xense-devel-request@lists.xensource.com?subject=help>
List-id: "A discussion list for those developing security enhancements for Xen." <xense-devel.lists.xensource.com>
List-post: <mailto:xense-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xense-devel>, <mailto:xense-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xense-devel>, <mailto:xense-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xense-devel-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AccZQBPgjbA23/+2QUOOIz1N3zUarAAGPIiAAAL2oJA=
Thread-topic: [Xense-devel] Vtpm_manager getting TPM_NOSPACE
Vinnie,
     This happened on a fresh boot.  Could it be that vtpm_manager has
too many keys it's trying to load into the TPM?  For instance, over time
more keys got added to the persistent storage file and then today it
couldn't load them all.  Unfortunately I deleted the vtpm data files
after I reset the TPM.

Ozzie

--
Justin D. Osborn
Software Engineer
Information Operations
JHU/APL
 

> -----Original Message-----
> From: Scarlata, Vincent R [mailto:vincent.r.scarlata@xxxxxxxxx] 
> Sent: Wednesday, December 06, 2006 12:12 PM
> To: Osborn, Justin D.; xense-devel@xxxxxxxxxxxxxxxxxxx
> Subject: RE: [Xense-devel] Vtpm_manager getting TPM_NOSPACE
> 
> Yes, on a sigkill the manager does clean up after itself. 
> When did you get the TPM_NOSPACE error? Were you running the 
> manager or some other TPM application before running the 
> manager and getting this error? On every power cycle, the TPM 
> unloads all it's keys and authorization sessions automatically. 
> 
> So if you get this error on a fresh boot, the TPM is not 
> properly flushing, which is a security issue that they need 
> to fix. If you ran the vtpm manager, shut it down, and 
> started it again and got this problem, then you've found a 
> bug in the manager showing that it's not cleaning up fully. 
> If you ran something else and then the manager, then that 
> something else isn't properly cleaning up.
> 
> -Vinnie Scarlata  
> 
> -----Original Message-----
> From: xense-devel-bounces@xxxxxxxxxxxxxxxxxxx
> [mailto:xense-devel-bounces@xxxxxxxxxxxxxxxxxxx] On Behalf Of 
> Osborn, Justin D.
> Sent: Wednesday, December 06, 2006 6:09 AM
> To: xense-devel@xxxxxxxxxxxxxxxxxxx
> Subject: [Xense-devel] Vtpm_manager getting TPM_NOSPACE
> 
> Hi all,
>      I've been working on a project for a while that uses xen 
> and the vtpm.  We have a DomU configured to use a vtpm 
> instance.  When I brought up the box this morning, 
> vtpm_manager failed to start, giving me an error that it 
> received TPM_NOSPACE when trying to load a key.  Is this a bug?
> 
> I usually shut the machine down with /sbin/halt or 
> /sbin/reboot, which just kills vtpm_managerd.  I assume 
> vtpm_managerd is supposed to clean up after itself.  So is 
> there a certain way I should kill vtpm_managerd?
> Or is this a bug?
> 
> Thanks,
> Ozzie
> 
> --
> Justin D. Osborn
> Software Engineer
> Information Operations
> JHU/APL
> 
> _______________________________________________
> Xense-devel mailing list
> Xense-devel@xxxxxxxxxxxxxxxxxxx
> http://lists.xensource.com/xense-devel
> 

_______________________________________________
Xense-devel mailing list
Xense-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xense-devel

<Prev in Thread] Current Thread [Next in Thread>