xref: /linux-6.15/drivers/char/tpm/Kconfig (revision 033ee84e)
1# SPDX-License-Identifier: GPL-2.0-only
2#
3# TPM device configuration
4#
5
6menuconfig TCG_TPM
7	tristate "TPM Hardware Support"
8	depends on HAS_IOMEM
9	imply SECURITYFS
10	select CRYPTO
11	select CRYPTO_HASH_INFO
12	help
13	  If you have a TPM security chip in your system, which
14	  implements the Trusted Computing Group's specification,
15	  say Yes and it will be accessible from within Linux.  For
16	  more information see <http://www.trustedcomputinggroup.org>.
17	  An implementation of the Trusted Software Stack (TSS), the
18	  userspace enablement piece of the specification, can be
19	  obtained at: <http://sourceforge.net/projects/trousers>.  To
20	  compile this driver as a module, choose M here; the module
21	  will be called tpm. If unsure, say N.
22	  Notes:
23	  1) For more TPM drivers enable CONFIG_PNP, CONFIG_ACPI
24	  and CONFIG_PNPACPI.
25	  2) Without ACPI enabled, the BIOS event log won't be accessible,
26	  which is required to validate the PCR 0-7 values.
27
28if TCG_TPM
29
30config TCG_TPM2_HMAC
31	bool "Use HMAC and encrypted transactions on the TPM bus"
32	default y
33	select CRYPTO_LIB_SHA256
34	help
35	  Setting this causes us to deploy a scheme which uses request
36	  and response HMACs in addition to encryption for
37	  communicating with the TPM to prevent or detect bus snooping
38	  and interposer attacks (see tpm-security.rst).  Saying Y
39	  here adds some encryption overhead to all kernel to TPM
40	  transactions.
41
42config HW_RANDOM_TPM
43	bool "TPM HW Random Number Generator support"
44	depends on TCG_TPM && HW_RANDOM && !(TCG_TPM=y && HW_RANDOM=m)
45	default y
46	help
47	  This setting exposes the TPM's Random Number Generator as a hwrng
48	  device. This allows the kernel to collect randomness from the TPM at
49	  boot, and provides the TPM randomines in /dev/hwrng.
50
51	  If unsure, say Y.
52
53config TCG_TIS_CORE
54	tristate
55	help
56	TCG TIS TPM core driver. It implements the TPM TCG TIS logic and hooks
57	into the TPM kernel APIs. Physical layers will register against it.
58
59config TCG_TIS
60	tristate "TPM Interface Specification 1.2 Interface / TPM 2.0 FIFO Interface"
61	depends on X86 || OF
62	select TCG_TIS_CORE
63	help
64	  If you have a TPM security chip that is compliant with the
65	  TCG TIS 1.2 TPM specification (TPM1.2) or the TCG PTP FIFO
66	  specification (TPM2.0) say Yes and it will be accessible from
67	  within Linux. To compile this driver as a module, choose  M here;
68	  the module will be called tpm_tis.
69
70config TCG_TIS_SPI
71	tristate "TPM Interface Specification 1.3 Interface / TPM 2.0 FIFO Interface - (SPI)"
72	depends on SPI
73	select TCG_TIS_CORE
74	help
75	  If you have a TPM security chip which is connected to a regular,
76	  non-tcg SPI master (i.e. most embedded platforms) that is compliant with the
77	  TCG TIS 1.3 TPM specification (TPM1.2) or the TCG PTP FIFO
78	  specification (TPM2.0) say Yes and it will be accessible from
79	  within Linux. To compile this driver as a module, choose  M here;
80	  the module will be called tpm_tis_spi.
81
82config TCG_TIS_SPI_CR50
83	bool "Cr50 SPI Interface"
84	depends on TCG_TIS_SPI
85	help
86	  If you have a H1 secure module running Cr50 firmware on SPI bus,
87	  say Yes and it will be accessible from within Linux.
88
89config TCG_TIS_I2C
90	tristate "TPM Interface Specification 1.3 Interface / TPM 2.0 FIFO Interface - (I2C - generic)"
91	depends on I2C
92	select CRC_CCITT
93	select TCG_TIS_CORE
94	help
95	  If you have a TPM security chip, compliant with the TCG TPM PTP
96	  (I2C interface) specification and connected to an I2C bus master,
97	  say Yes and it will be accessible from within Linux.
98	  To compile this driver as a module, choose M here;
99	  the module will be called tpm_tis_i2c.
100
101config TCG_TIS_SYNQUACER
102	tristate "TPM Interface Specification 1.2 Interface / TPM 2.0 FIFO Interface (MMIO - SynQuacer)"
103	depends on ARCH_SYNQUACER || COMPILE_TEST
104	select TCG_TIS_CORE
105	help
106	  If you have a TPM security chip that is compliant with the
107	  TCG TIS 1.2 TPM specification (TPM1.2) or the TCG PTP FIFO
108	  specification (TPM2.0) say Yes and it will be accessible from
109	  within Linux on Socionext SynQuacer platform.
110	  To compile this driver as a module, choose  M here;
111	  the module will be called tpm_tis_synquacer.
112
113config TCG_TIS_I2C_CR50
114	tristate "TPM Interface Specification 2.0 Interface (I2C - CR50)"
115	depends on I2C
116	help
117	  This is a driver for the Google cr50 I2C TPM interface which is a
118	  custom microcontroller and requires a custom i2c protocol interface
119	  to handle the limitations of the hardware.  To compile this driver
120	  as a module, choose M here; the module will be called tcg_tis_i2c_cr50.
121
122config TCG_TIS_I2C_ATMEL
123	tristate "TPM Interface Specification 1.2 Interface (I2C - Atmel)"
124	depends on I2C
125	help
126	  If you have an Atmel I2C TPM security chip say Yes and it will be
127	  accessible from within Linux.
128	  To compile this driver as a module, choose M here; the module will
129	  be called tpm_tis_i2c_atmel.
130
131config TCG_TIS_I2C_INFINEON
132	tristate "TPM Interface Specification 1.2 Interface (I2C - Infineon)"
133	depends on I2C
134	help
135	  If you have a TPM security chip that is compliant with the
136	  TCG TIS 1.2 TPM specification and Infineon's I2C Protocol Stack
137	  Specification 0.20 say Yes and it will be accessible from within
138	  Linux.
139	  To compile this driver as a module, choose M here; the module
140	  will be called tpm_i2c_infineon.
141
142config TCG_TIS_I2C_NUVOTON
143	tristate "TPM Interface Specification 1.2 Interface (I2C - Nuvoton)"
144	depends on I2C
145	help
146	  If you have a TPM security chip with an I2C interface from
147	  Nuvoton Technology Corp. say Yes and it will be accessible
148	  from within Linux.
149	  To compile this driver as a module, choose M here; the module
150	  will be called tpm_i2c_nuvoton.
151
152config TCG_NSC
153	tristate "National Semiconductor TPM Interface"
154	depends on X86
155	help
156	  If you have a TPM security chip from National Semiconductor
157	  say Yes and it will be accessible from within Linux.  To
158	  compile this driver as a module, choose M here; the module
159	  will be called tpm_nsc.
160
161config TCG_ATMEL
162	tristate "Atmel TPM Interface"
163	depends on PPC64 || HAS_IOPORT_MAP
164	depends on HAS_IOPORT
165	help
166	  If you have a TPM security chip from Atmel say Yes and it
167	  will be accessible from within Linux.  To compile this driver
168	  as a module, choose M here; the module will be called tpm_atmel.
169
170config TCG_INFINEON
171	tristate "Infineon Technologies TPM Interface"
172	depends on PNP || COMPILE_TEST
173	help
174	  If you have a TPM security chip from Infineon Technologies
175	  (either SLD 9630 TT 1.1 or SLB 9635 TT 1.2) say Yes and it
176	  will be accessible from within Linux.
177	  To compile this driver as a module, choose M here; the module
178	  will be called tpm_infineon.
179	  Further information on this driver and the supported hardware
180	  can be found at http://www.trust.rub.de/projects/linux-device-driver-infineon-tpm/
181
182config TCG_IBMVTPM
183	tristate "IBM VTPM Interface"
184	depends on PPC_PSERIES
185	help
186	  If you have IBM virtual TPM (VTPM) support say Yes and it
187	  will be accessible from within Linux.  To compile this driver
188	  as a module, choose M here; the module will be called tpm_ibmvtpm.
189
190config TCG_XEN
191	tristate "XEN TPM Interface"
192	depends on TCG_TPM && XEN
193	select XEN_XENBUS_FRONTEND
194	help
195	  If you want to make TPM support available to a Xen user domain,
196	  say Yes and it will be accessible from within Linux. See
197	  the manpages for xl, xl.conf, and docs/misc/vtpm.txt in
198	  the Xen source repository for more details.
199	  To compile this driver as a module, choose M here; the module
200	  will be called xen-tpmfront.
201
202config TCG_CRB
203	tristate "TPM 2.0 CRB Interface"
204	depends on ACPI
205	help
206	  If you have a TPM security chip that is compliant with the
207	  TCG CRB 2.0 TPM specification say Yes and it will be accessible
208	  from within Linux.  To compile this driver as a module, choose
209	  M here; the module will be called tpm_crb.
210
211config TCG_VTPM_PROXY
212	tristate "VTPM Proxy Interface"
213	depends on TCG_TPM
214	help
215	  This driver proxies for an emulated TPM (vTPM) running in userspace.
216	  A device /dev/vtpmx is provided that creates a device pair
217	  /dev/vtpmX and a server-side file descriptor on which the vTPM
218	  can receive commands.
219
220config TCG_FTPM_TEE
221	tristate "TEE based fTPM Interface"
222	depends on TEE && OPTEE
223	help
224	  This driver proxies for firmware TPM running in TEE.
225
226source "drivers/char/tpm/st33zp24/Kconfig"
227endif # TCG_TPM
228