The TPM itself can't parse the measurement log, so if you wanted some information that was sealed in such a way that changing the kernel would prevent access to it but changing the command line was fine, you need to use different PCRs.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
no subject
Date: 2015-09-24 04:29 pm (UTC)