HomeFreeBSD

Allow using TPM as entropy source.

Description

Allow using TPM as entropy source.

TPM has a built-in RNG, with its own entropy source.
The driver was extended to harvest 16 random bytes from TPM every 10 seconds.
A new build option "TPM_HARVEST" was introduced - for now, however, it
is not enabled by default in the GENERIC config.

Submitted by: Kornel Duleba <mindal@semihalf.com>
Reviewed by: markm, delphij
Approved by: secteam
Obtained from: Semihalf
Sponsored by: Stormshield
Differential Revision: https://reviews.freebsd.org/D19620

Details

Provenance
mwAuthored on
Reviewer
markm
Differential Revision
D19620: Add an option to use TPM as entropy source
Parents
rS345437: The check for $ippool_rules in start_cmd is tautological.
Branches
Unknown
Tags
Unknown