mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
3ab06d77fb
pvattest is a tool to attest an IBM Secure Execution guest. In a trusted environment, one can create a request using `pvattest create`. To get a measurement of an untrusted IBM Secure Execution guest call 'pvattest perform'. Again in a trusted environment, call 'pvattest verify' to verify that the measurement is the expected one. The tool runs on s390 and x86. It has the same requirements like libpv and therefore requires openssl v1.1.1+, glib2.56+, and libcurl. Additionally, to measure, the linux kernel must provide the Ultravisor userspace interface `uvdevice` at /dev/uv and must be executed on an IBM Secure Execution guest on hardware with Ultravisor attestation support, like IBM z16 or later. Signed-off-by: Steffen Eiden <seiden@linux.ibm.com> Reviewed-by: Marc Hartmayer <mhartmay@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
48 lines
1.4 KiB
Groff
48 lines
1.4 KiB
Groff
.\" Copyright 2022 IBM Corp.
|
|
.\" s390-tools is free software; you can redistribute it and/or modify
|
|
.\" it under the terms of the MIT license. See LICENSE for details.
|
|
.\"
|
|
.TH pvattest-perform 1 "07 June 2022" "s390-tools" "Attestation Manual"
|
|
.nh
|
|
.ad l
|
|
.SH NAME
|
|
\fBpvattest [OPTION?] perform [OPTIONS] \fP- execute an attestation measurement request
|
|
\fB
|
|
.SH DESCRIPTION
|
|
Run a measurement of this system using '/dev/uv'. Works only if this device is available and the attestation Ultravisor facility is present. The input must be an attestation request created with 'pvattest create'. Output will contain the original request, the attestation measurement result, the configuration UID, and if requested in the request Additional Data.
|
|
.RE
|
|
.PP
|
|
|
|
.SH OPTIONS
|
|
.TP
|
|
.B
|
|
\fB-h\fP, \fB--help\fP
|
|
Show help options
|
|
.TP
|
|
.B
|
|
\fB-i\fP, \fB--input\fP=\fBFILE\fP
|
|
\fBFILE\fP specifies the attestation request as input.
|
|
.TP
|
|
.B
|
|
\fB-o\fP, \fB--output\fP=\fBFILE\fP
|
|
\fBFILE\fP specifies the output for the attestation result.
|
|
.TP
|
|
.B
|
|
\fB-V\fP, \fB--verbose\fP
|
|
Provide more detailed output (optional)
|
|
.RE
|
|
.PP
|
|
|
|
.SH EXAMPLE
|
|
Perform an attestation measurement with the attestation request 'arcb.bin' and write the output to 'measurement.bin'.
|
|
.PP
|
|
.nf
|
|
.fam C
|
|
pvattest perform --input attreq.bin --output attresp.bin
|
|
|
|
|
|
.fam T
|
|
.fi
|
|
.SH SEE ALSO
|
|
\fBpvattest\fP(1), \fBpvattest-create\fP(1), \fBpvattest-verify\fP(1)
|