iadgovuser26
|
bf8ef387c1
|
Merge pull request #407 from nsacyber/issue-381
[#381] Update RIM validation in ACA
|
2021-12-16 10:39:58 -05:00 |
|
iadgovuser29
|
da9c8469ba
|
Re-creating the componentidentifer here lost important information.
|
2021-12-10 20:58:44 -05:00 |
|
iadgovuser29
|
e22d95c2e6
|
Modified so PCI ID translation will highlight delta certs and show in Tooltips
|
2021-12-10 09:07:28 -05:00 |
|
Cyrus
|
9b790cb805
|
checking for class cast now. Highlighting appears.
|
2021-12-03 17:01:18 -05:00 |
|
Cyrus
|
6337367ba9
|
Added Pci IDs translate to the HIRS_Util module for the supply chain validator process so that the hash can match up for highlighting failed components.
|
2021-12-03 16:01:04 -05:00 |
|
iadgovuser29
|
95c5e40f89
|
Utilize protobuf to parse claim response. Work on array handling on ACA.
|
2021-11-23 22:01:16 -05:00 |
|
Cyrus
|
483099a273
|
Updated the policy code to modify the measurement array length and ignore PCR 10 as well.
|
2021-11-23 10:06:21 -05:00 |
|
Cyrus
|
4c46758d9a
|
This commit is a feature update. The IMA PCR enable/diable is being enhanced to update the mask the provisioner uses to pull the quote from the TPM. This code will send down a string range of PCR values that excludes PCR 10. The quote that is returned should be a composite without the PCR 10. There will be a log statement in this commit that should be removed.
|
2021-11-23 09:36:00 -05:00 |
|
chubtub
|
1eca360a4d
|
Modify log messages so that validation failures from certs in the keystore that are not actually in the chain do not raise undue attention
|
2021-11-19 01:50:05 -05:00 |
|
5B96790E3664F40075A67E6ADF737EDB15B4408DBC91A81228B31537B0CE3E26
|
3f091a3827
|
Merge pull request #415 from nsacyber/issue/414
[#414] Handle MODIFIED component without serial number
|
2021-11-18 08:54:09 -05:00 |
|
chubtub
|
23a086c925
|
Merge branch 'issue-381' of github.com:nsacyber/HIRS into issue-381
|
2021-11-17 10:06:58 -05:00 |
|
chubtub
|
d5fcd06902
|
Add error handling to clarify endorsement validation error
|
2021-11-16 16:59:56 -05:00 |
|
Cyrus
|
d31b710824
|
This is a test run to ignore endorsement credential verification during firmware testing.
|
2021-11-12 14:24:33 -05:00 |
|
Cyrus
|
c944aab335
|
Added a log statement to get more information about the certificate that is failing signature verification.
|
2021-11-12 11:31:00 -05:00 |
|
chubtub
|
d183504a3f
|
Merge branch 'master' into issue-381
|
2021-11-10 10:08:42 -05:00 |
|
Cyrus
|
0934b3106f
|
Merge pull request #420 from nsacyber/base-rim-link-fix
RimLinkHash Fix
|
2021-11-10 10:06:11 -05:00 |
|
Cyrus
|
70d92c4b38
|
Merge pull request #417 from nsacyber/issue-404
[#404] PXE Policy options
|
2021-11-10 10:05:52 -05:00 |
|
Cyrus
|
04b050de15
|
The rimlinkhash meta information wasn't linking up with the associated swidtag. This is because the wrong hash look up was being used. Previously when the hexDecHash and base64Hash were implemented, the main focus was on the rimel and not the swidtag.
|
2021-11-10 09:50:17 -05:00 |
|
Cyrus
|
2d9fb19d38
|
Updated the new polices after doing a bit of testing to make sure that they do ignore when there is a failure on that specific bit.
|
2021-11-10 07:27:33 -05:00 |
|
chubtub
|
0c233ae771
|
Set signature validity so that the ACA can report accurately
|
2021-11-08 14:51:38 -05:00 |
|
chubtub
|
3a6be133eb
|
Checkstyle changes
|
2021-11-08 14:51:38 -05:00 |
|
chubtub
|
bc7e07583f
|
Match only the actual extension bytes of the SKID
|
2021-11-08 14:51:38 -05:00 |
|
chubtub
|
962ca45bb7
|
Modify ACA RIM validation to search for a signing cert if the base RIM does not have an embedded cert. Validate the ca chain of the found signing cert.
|
2021-11-08 14:46:04 -05:00 |
|
Cyrus
|
f0ea84d199
|
I added code to do different masks on the pcr selection, but that was not needed. So I just uncommented the one section of ignore not being used.
|
2021-11-05 16:11:28 -04:00 |
|
chubtub
|
7bb9d8698d
|
Merge pull request #408 from nsacyber/support-rim-filename-correction
Support RIM Filename Fix
|
2021-11-05 08:57:06 -04:00 |
|
Cyrus
|
e82de12341
|
Updated the ignore OS events check with the last rule for #404
|
2021-11-01 09:35:36 -04:00 |
|
Cyrus
|
fe617ea948
|
Updated the policy code to ignore based on the TPM Log Event. Added in the code for OS Events.
|
2021-10-29 20:24:46 -04:00 |
|
Cyrus
|
aae6845730
|
Initial Commit. This adds the visual object to the policy page.
|
2021-10-29 14:55:23 -04:00 |
|
iadgovuser29
|
4403a98b3b
|
[#414] Handle MODIFIED component without serial number
|
2021-10-29 09:02:56 -04:00 |
|
iadgovuser29
|
867833dc9d
|
[#411] Changed assumption regarding Delta cert components with ADDED status.
|
2021-10-27 14:14:09 -04:00 |
|
iadgovuser29
|
647c88d16b
|
[#409] Fixed one problem with delta component checking.
|
2021-10-26 15:53:05 -04:00 |
|
Cyrus
|
bb6ec6cc4b
|
The rim hash validation icon is coming up red when both base and support RIMs are loaded. This fixes that issue.
|
2021-10-26 11:09:36 -04:00 |
|
iadgovuser29
|
e8085aae0f
|
[#401] Changed instanceof check and error message.
|
2021-10-17 21:51:29 -04:00 |
|
Cyrus
|
f8a3ccd962
|
This is an initial commit updates the policy page. Adds additional policies for generating a DevID. The underlying code doesn't actually generate one yet. But the SupplyChainPolicy holds the flags.
|
2021-09-17 07:55:44 -04:00 |
|
Cyrus
|
14ecd9832e
|
Updated unit tested to correct the failures that were occurring because of the updated code changes.
|
2021-08-30 11:44:37 -04:00 |
|
Cyrus
|
cf5472242b
|
Merge pull request #393 from nsacyber/uefi-test-update
Checkstyle fix on a Unit Test
|
2021-08-24 09:42:12 -04:00 |
|
Cyrus
|
5a26093d57
|
Missed and update for a method that was updated with a new exception thrown.
|
2021-08-20 13:47:20 -04:00 |
|
iadgovuser26
|
71666542c1
|
Merge pull request #392 from nsacyber/uefi-test-update
UEFI Unit Test Update
|
2021-08-20 12:16:35 -04:00 |
|
iadgovuser26
|
761fb6aaa9
|
Merge pull request #391 from nsacyber/fix-certificatetest-testisissuer
Fix for faulty logic in CertificateTest.testIsIssuer
|
2021-08-20 12:16:23 -04:00 |
|
iadgovuser26
|
793d21ae5b
|
Merge pull request #390 from nsacyber/fix-testappraiser-name
Fixing one unit test revealed additional test updates.
|
2021-08-20 12:16:04 -04:00 |
|
iadgovuser26
|
3132a590e1
|
Merge pull request #388 from nsacyber/ignore-tpmbaselinegeneratortest-csvgeneratortest
Ignore tests from TPMBaselineGeneratorTest and ima.CSVGeneratorTest.
|
2021-08-20 12:15:35 -04:00 |
|
Cyrus
|
61497809f5
|
Updated the UefiGuid to have the vendor json file get passed in. This updates the unit test and fixes the issue.
|
2021-08-20 09:19:01 -04:00 |
|
iadgovuser26
|
9fbbf81ada
|
Merge pull request #389 from nsacyber/eventLogTesFix
updated TCGEventLogEventsTest
|
2021-08-18 16:20:16 -04:00 |
|
iadgovuser29
|
7e3eaf4c5c
|
Fix for faulty logic in CertificateTest.testIsIssuer
|
2021-08-18 14:09:27 -04:00 |
|
iadgovuser29
|
f9a32e3f52
|
Fixing one unit test revealed additional test updates.
|
2021-08-18 13:29:49 -04:00 |
|
chubtub
|
c76a8a074e
|
Minor code clean up
|
2021-08-18 09:15:59 -04:00 |
|
iadgovuser29
|
b8741039a9
|
Ignore tests from TPMBaselineGeneratorTest and ima.CSVGeneratorTest.
|
2021-08-17 17:59:34 -04:00 |
|
lareine
|
32887eb598
|
updated TCGEventLogEventsTest
|
2021-08-17 17:30:45 -04:00 |
|
iadgovuser29
|
f54e1a15d0
|
Fixed a certificate conversion issue.
|
2021-08-17 17:21:32 -04:00 |
|
chubtub
|
dc7301e8a6
|
Update overloaded validateCertChain to check cert chain consistently
|
2021-08-17 14:41:00 -04:00 |
|