summaryrefslogtreecommitdiff
path: root/README.tpm
diff options
context:
space:
mode:
authorMathieu Trudel-Lapierre <mathieu.trudel-lapierre@canonical.com>2018-07-24 16:24:23 -0400
committerMathieu Trudel-Lapierre <mathieu.trudel-lapierre@canonical.com>2018-07-24 16:24:23 -0400
commitf892ac66084ab0315adb0c52e4a39b518730d023 (patch)
tree0b41430bab3e1cf51e37476a5e6548f639cb7ec6 /README.tpm
parent6215e920e71f5c6c43189f27b755e7a3238ad396 (diff)
downloadefi-boot-shim-upstream/15+1531942534.dd3230d.tar.gz
efi-boot-shim-upstream/15+1531942534.dd3230d.zip
New upstream version 15+1531942534.dd3230dupstream/15+1531942534.dd3230d
Diffstat (limited to 'README.tpm')
-rw-r--r--README.tpm2
1 files changed, 2 insertions, 0 deletions
diff --git a/README.tpm b/README.tpm
index 261bcd05..b7314f12 100644
--- a/README.tpm
+++ b/README.tpm
@@ -3,6 +3,8 @@ The following PCRs are extended by shim:
PCR4:
- the Authenticode hash of the binary being loaded will be extended into
PCR4 before SB verification.
+- the hash of any binary for which Verify is called through the shim_lock
+ protocol
PCR7:
- Any certificate in one of our certificate databases that matches a binary