Messages in this thread |  | | Date | Wed, 18 Feb 2026 20:56:14 -0400 | | From | Jason Gunthorpe <> | | Subject | Re: [RFC v3 00/27] lib: Rust implementation of SPDM |
| |
On Wed, Feb 18, 2026 at 03:40:10PM -0800, dan.j.williams@intel.com wrote:
> So one proposal to get the x509 pre-work upstream is to extend the TSM > core (drivers/pci/tsm.c) to export the certificates in sysfs, and update > the existing "authenticated" attribute to reflect the result of cert > chain validation.
Why do we want the validate the cert chain in the kernel? That sounds like something the verifier should do?
And not sure we should be dumping any certs in sysfs if the plan for the other stuff is netlink, it should be consistent I think.
Though it is a good idea to do something with the TSM too..
Jason
|  |