<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Open Source Security &#187; Trusted Computing</title>
	<atom:link href="http://www.ratliff.net/blog/category/trusted-computing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ratliff.net/blog</link>
	<description>A blog about open source and security and open source security</description>
	<pubDate>Mon, 10 Nov 2008 21:33:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>Installing and configuring eCryptfs with a trusted platform module (TPM) key</title>
		<link>http://www.ratliff.net/blog/2008/11/10/installing-and-configuring-ecryptfs-with-a-trusted-platform-module-tpm-key/</link>
		<comments>http://www.ratliff.net/blog/2008/11/10/installing-and-configuring-ecryptfs-with-a-trusted-platform-module-tpm-key/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 21:33:55 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[eCryptfs]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=80</guid>
		<description><![CDATA[Mike Halcrow has written a paper on Installing and configuring eCryptfs with a trusted platform module (TPM) key. This paper is available on IBM Systems Information Center along with a bunch of other step-by-step guides.
This paper describes how to use a TPM key directly with eCryptfs. It demonstrates the flexibility of eCryptfs&#8217; pluggable key module [...]]]></description>
			<content:encoded><![CDATA[<p>Mike Halcrow has written a paper on <a href="http://publib.boulder.ibm.com/infocenter/systems/topic/liaai/ecrypts/BPeCryptfs.pdf">Installing and configuring eCryptfs with a trusted platform module (TPM) key</a>. This paper is available on <a href="http://publib.boulder.ibm.com/infocenter/systems/index.jsp?topic=/liaai/liaaiblueprint.htm">IBM Systems Information Center</a> along with a bunch of other step-by-step guides.<br />
This paper describes how to use a TPM key directly with eCryptfs. It demonstrates the flexibility of eCryptfs&#8217; pluggable key module framework. Since the TPM wasn&#8217;t designed to do bulk encryption, if you actually set eCryptfs up this way, you&#8217;ll get pretty low performance, but it is an interesting exercise nonetheless and if you have small bits of information that you want strongly protected, this does provide one good option. I hear that Mike is working on replicating this experiment with a wrappered key which should provide much better performance but requires a little additional code.<br />
In addition to showing how to integrated the TPM with eCryptfs, this paper also contains a step-by-step descriptions on how to do ancillary operations like how to enable encrypted swap in Red Hat Enterprise Linux 5.2 and how to get your TPM up and operational. This side content alone makes the paper useful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2008/11/10/installing-and-configuring-ecryptfs-with-a-trusted-platform-module-tpm-key/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Red Hat Enterprise Linux 5.2 contains two security Technology Previews</title>
		<link>http://www.ratliff.net/blog/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/</link>
		<comments>http://www.ratliff.net/blog/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/#comments</comments>
		<pubDate>Wed, 21 May 2008 21:47:29 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Products]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=72</guid>
		<description><![CDATA[Red Hat Enterprise Linux 5.2 was released today. That is significant news in and of itself, but I am especially excited because it contains Technology Previews of  eCryptfs, TrouSerS, and tpm-tools! As Technology Previews, they are not yet supported for production use, but this is the first step to allow for experimentation and time [...]]]></description>
			<content:encoded><![CDATA[<p>Red Hat Enterprise Linux 5.2 was <a href="http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/">released</a> today. That is significant news in and of itself, but I am especially excited because it contains Technology Previews of  <a href="http://ecryptfs.sourceforge.net/">eCryptfs</a>, <a href="http://trousers.sourceforge.net/">TrouSerS</a>, and tpm-tools! As Technology Previews, they are not yet supported for production use, but this is the first step to allow for experimentation and time for ripening. I&#8217;m happy to see Red Hat&#8217;s continued dedication to security. If you try these packages out in RHEL, I&#8217;d love to hear of any successes or problems that you encounter.</p>
<p>[1] <a href="http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/">http://www.press.redhat.com/2008/05/21/red-hat-enterprise-linux-52/</a><br />
[2] <a href="http://ecryptfs.sourceforge.net/">http://ecryptfs.sourceforge.net/</a><br />
[3] <a href="http://trousers.sourceforge.net/">http://trousers.sourceforge.net/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2008/05/21/red-hat-enterprise-linux-52-contains-two-security-technology-previews/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hal Finney&#8217;s Experimental Privacy CA</title>
		<link>http://www.ratliff.net/blog/2008/01/14/hal-finneys-experimental-privacy-ca/</link>
		<comments>http://www.ratliff.net/blog/2008/01/14/hal-finneys-experimental-privacy-ca/#comments</comments>
		<pubDate>Mon, 14 Jan 2008 21:34:52 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2008/01/14/hal-finneys-experimental-privacy-ca/</guid>
		<description><![CDATA[A longstanding limitation of doing remote attestation between &#8220;strangers&#8221; has been eased through some experimental work that Hal Finney recently announced on the TrouSerS user&#8217;s list. Hal has announced that he has created a Privacy CA at PrivacyCA.com. Question 2.1 of the TrouSerS FAQ contains a graphic showing the prerequisite pieces for doing remote attestation. [...]]]></description>
			<content:encoded><![CDATA[<p>A longstanding limitation of doing remote attestation between &#8220;strangers&#8221; has been eased through some experimental work that <a href="http://sourceforge.net/mailarchive/forum.php?thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users">Hal Finney recently announced</a> on the TrouSerS user&#8217;s list. Hal has announced that he has created a Privacy CA at <a href="http://privacyca.com/">PrivacyCA.com</a>. <a href="http://trousers.sourceforge.net/faq.html#2.1">Question 2.1 of the TrouSerS FAQ</a> contains a graphic showing the prerequisite pieces for doing remote attestation. Hal has filled in the Privacy CA and notes that Infineon does supply the Endorsement Credential. He also provides a &#8220;test and debug mode&#8221; so that users of other TPMs can still experiment with the service without the guarantee that they are using real TPMs. Up to now, attestation keys had to be exchanged via sneaker net (manual exchange and verification before attestation was possible) to enable machines to do remote attestation. Hal&#8217;s announcement represents a great leap forward in the usefulness of TPMs.</p>
<p>1. <a href="http://sourceforge.net/mailarchive/forum.php?thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users">http://sourceforge.net/mailarchive/forum.php?<br />
thread_name=da7b3ce30801131643j74be4064l52daa8c0e90efa83%40mail.gmail.com&#038;forum_name=trousers-users</a><br />
2. <a href="http://privacyca.com/">PrivacyCA.com</a><br />
2. <a href="http://trousers.sourceforge.net/faq.html#2.1">http://trousers.sourceforge.net/faq.html#2.1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2008/01/14/hal-finneys-experimental-privacy-ca/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trusted Computing Group Blog</title>
		<link>http://www.ratliff.net/blog/2007/12/21/trusted-computing-group-blog/</link>
		<comments>http://www.ratliff.net/blog/2007/12/21/trusted-computing-group-blog/#comments</comments>
		<pubDate>Sat, 22 Dec 2007 03:45:06 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/12/21/trusted-computing-group-blog/</guid>
		<description><![CDATA[The Trusted Computing Group has launched a new group blog. The actual bloggers haven&#8217;t yet been announced, but presuming that they will include some people who are already actively writing about Trusted Computing (say Steve Hanna, Marion Weber, Dave Challener, perhaps) it will be a blog worthy of attention.
]]></description>
			<content:encoded><![CDATA[<p>The Trusted Computing Group has launched a new <a href="https://www.trustedcomputinggroup.org/blog/">group blog</a>. The actual bloggers haven&#8217;t yet been announced, but presuming that they will include some people who are already actively writing about Trusted Computing (say Steve Hanna, Marion Weber, Dave Challener, perhaps) it will be a blog worthy of attention.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/12/21/trusted-computing-group-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New book on Trusted Computing</title>
		<link>http://www.ratliff.net/blog/2007/12/19/new-book-on-trusted-computing/</link>
		<comments>http://www.ratliff.net/blog/2007/12/19/new-book-on-trusted-computing/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 21:59:18 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Products]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/12/19/new-book-on-trusted-computing/</guid>
		<description><![CDATA[Current and former co-workers, Kent Yoder, Dave Challener, Ryan Catherman, Dave Safford, and Leedert van Doorn have written a book called A Practical Guide to Trusted Computing. It&#8217;s now available for pre-order on Amazon and will available on Jan. 7, 2008. The authors have been instrumental in the creation of the TCG specs and key [...]]]></description>
			<content:encoded><![CDATA[<p>Current and former co-workers, Kent Yoder, Dave Challener, Ryan Catherman, Dave Safford, and Leedert van Doorn have written a book called <code>A Practical Guide to Trusted Computing</code>. It&#8217;s now available for pre-order on Amazon and will available on Jan. 7, 2008. The authors have been instrumental in the creation of the TCG specs and key open source software, for example, Dave led the TSS Working Group for years and Leendert was on the Board of Directors. I reviewed an early copy of the book almost exactly a year ago. My favorite parts of the version that I read were the chapters on TSS along with the sample code for how to use the TSS API and the chapter on use cases for Trusted Computing (for the sheer fun of it). I think that it definitely lives up to its billing as a practical guide and it provides a complete grounding in the concepts of trust, attestation, measurement, etc. that are foundational to Trusted Computing. It is very readable and is a faster read and shorter than it seems because of the reference information included. I haven&#8217;t yet seen the ultimate version of the book, but I&#8217;m eagerly awaiting my copy from Amazon. Congratulations to the authors for sticking through the long haul and providing such a useful book!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/12/19/new-book-on-trusted-computing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Knoppix Live Image with Trusted Computing Features</title>
		<link>http://www.ratliff.net/blog/2007/12/03/knoppix-live-image-with-trusted-computing-features/</link>
		<comments>http://www.ratliff.net/blog/2007/12/03/knoppix-live-image-with-trusted-computing-features/#comments</comments>
		<pubDate>Mon, 03 Dec 2007 20:46:21 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Linux]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/12/03/knoppix-live-image-with-trusted-computing-features/</guid>
		<description><![CDATA[If you want to try out some of the Trusted Computing features but don&#8217;t want to add them to your running system, check out this version of Knoppix  that Japan&#8217;s National Institute of Advanced Industrial Science and Technology (AIST) produced with IBM Tokyo Research Lab. It includes Grub-IMA, Linux-IMA, TrouSerS, tpm-tools and TPM Manager(by [...]]]></description>
			<content:encoded><![CDATA[<p>If you want to try out some of the Trusted Computing features but don&#8217;t want to add them to your running system, check out this version of Knoppix  that Japan&#8217;s National Institute of Advanced Industrial Science and Technology (AIST) produced with IBM Tokyo Research Lab. It includes Grub-IMA, Linux-IMA, TrouSerS, tpm-tools and TPM Manager(by rub.de). More features are still being developed. Thanks to Seiji Munetoh for pointing this out to me. I downloaded it and tried it on my T42p and it is very clean and slick.</p>
<p>It&#8217;s available from <a href="http://unit.aist.go.jp/itri/knoppix/index-en.html">http://unit.aist.go.jp/itri/knoppix/index-en.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/12/03/knoppix-live-image-with-trusted-computing-features/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Steve Hanna&#8217;s article on NAC</title>
		<link>http://www.ratliff.net/blog/2007/12/03/steve-hannas-article-on-nac/</link>
		<comments>http://www.ratliff.net/blog/2007/12/03/steve-hannas-article-on-nac/#comments</comments>
		<pubDate>Mon, 03 Dec 2007 16:06:48 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/12/03/steve-hannas-article-on-nac/</guid>
		<description><![CDATA[Steve Hanna has written an excellent introductory article[1] on Network Access Control (NAC) discussing the motivations for implementing NAC and how Trusted Computing can help further secure NAC. Trusted Computing works well here because while the endpoint can still lie, it gets noticed that the endpoint is lying even if the exact lie is not [...]]]></description>
			<content:encoded><![CDATA[<p>Steve Hanna has written an <a href="http://www.esj.com/news/print.aspx?editorialsId=2904">excellent introductory article</a>[1] on Network Access Control (NAC) discussing the motivations for implementing NAC and how Trusted Computing can help further secure NAC. Trusted Computing works well here because while the endpoint can still lie, it gets noticed that the endpoint is lying even if the exact lie is not known. The lie is detected because the measurement log no longer matches the signed quote of the PCR values. IBM Research wrote an excellent paper in 2004 describing attestation in detail as implemented on a Linux system: <a href="https://www.trustedcomputinggroup.org/press/news_articles/rc23363.pdf">The Role of TPM in Enterprise Security</a>[2].</p>
<p>[1] http://www.esj.com/news/print.aspx?editorialsId=2904<br />
[2] https://www.trustedcomputinggroup.org/press/news_articles/rc23363.pdf</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/12/03/steve-hannas-article-on-nac/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ENISA Quarterly Features Trusted Computing</title>
		<link>http://www.ratliff.net/blog/2007/11/28/enisa-quarterly-features-trusted-computing/</link>
		<comments>http://www.ratliff.net/blog/2007/11/28/enisa-quarterly-features-trusted-computing/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 23:19:07 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/11/28/enisa-quarterly-features-trusted-computing/</guid>
		<description><![CDATA[The current magazine from the European Network and information Security Agency (ENISA) highlights Trusted Computing in their current issue of ENISA Quarterly [1]. There are four articles on Trusted Computing - one which compares TC to automobile airbags. There is an interesting article on Trusted Computing from a European perspective which covered the workshop by [...]]]></description>
			<content:encoded><![CDATA[<p>The current magazine from the European Network and information Security Agency (ENISA) highlights Trusted Computing in their current issue of <a href="http://www.enisa.europa.eu/doc/pdf/publications/enisa_quarterly_09_07.pdf">ENISA Quarterly</a> [1]. There are four articles on Trusted Computing - one which compares TC to automobile airbags. There is an interesting article on Trusted Computing from a European perspective which covered the workshop by the same name held in Germany earlier this year. Another article touches on the OpenTC project&#8217;s goal of providing European citizens &#8220;informational self-determination&#8221; in a secure context. Also noteworthy is the call for papers for Trust 2008.</p>
<p><BR><BR><br />
[1] http://www.enisa.europa.eu/doc/pdf/publications/enisa_quarterly_09_07.pdf</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/11/28/enisa-quarterly-features-trusted-computing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trusted Computing and the Trough of Disillusionment</title>
		<link>http://www.ratliff.net/blog/2007/10/25/trusted-computing-and-the-trough-of-disallusionment/</link>
		<comments>http://www.ratliff.net/blog/2007/10/25/trusted-computing-and-the-trough-of-disallusionment/#comments</comments>
		<pubDate>Fri, 26 Oct 2007 01:56:52 +0000</pubDate>
		<dc:creator>Emily Ratliff</dc:creator>
		
		<category><![CDATA[Planet LTC]]></category>

		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://www.ratliff.net/blog/index.php/2007/10/25/trusted-computing-and-the-trough-of-disallusionment/</guid>
		<description><![CDATA[RSA London is going on this week and professional blogger David Lacey is blogging that not much interesting is going on, but that he was very excited to meet Steve Hanna. Steve says that 2008 is going to be the year that Trusted Computing breaks out.[1] I hope he is right! Gartner for 2006 still [...]]]></description>
			<content:encoded><![CDATA[<p>RSA London is going on this week and professional blogger David Lacey is blogging that not much interesting is going on, but that he was very excited to meet Steve Hanna. Steve says that 2008 is going to be the year that Trusted Computing breaks out.[1] I hope he is right! Gartner for 2006 still has Trusted Computing sliding into the trough.[2] But the saddest testament to the slow uptake on Trusted Computing is that Gartner uses it as an example technology to explain two different factors that can cause a technology to have a &#8220;Long Fuse&#8221; (that is to spend more time than average in the Trough of Disillusionment).[3] I am starting to see some signs that the deep trough that the technology has been in the past couple of years is coming to an end (more on this later) and Steve&#8217;s optimism is heartening.</p>
<p>[1]<a href="http://www.computerweekly.com/blogs/david_lacey/2007/10/trusted-computing-hits-the-roa.html">David Lacey, Trusted Computing Hits the Road</a><br />
[2]<a href="http://www.gartner.com/it/products/hc/hc.jsp#w">Gartner&#8217;s Hype Cycle Reports</a> Click on Information Security and look at the table of contents to see where Trusted Computing Platform is listed in the latest Hype Cycle.<br />
[3]<a href="http://www.gartner.com/DisplayDocument?id=509085#5_3%3C!--%20entry%20label%2014--%3E">Understanding Gartner&#8217;s Hype Cycles</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ratliff.net/blog/2007/10/25/trusted-computing-and-the-trough-of-disallusionment/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
