1# SPDX-License-Identifier: GPL-2.0-only 2# 3# TPM device configuration 4# 5 6menuconfig TCG_TPM 7 tristate "TPM Hardware Support" 8 depends on HAS_IOMEM 9 imply SECURITYFS 10 select CRYPTO 11 select CRYPTO_HASH_INFO 12 help 13 If you have a TPM security chip in your system, which 14 implements the Trusted Computing Group's specification, 15 say Yes and it will be accessible from within Linux. For 16 more information see <http://www.trustedcomputinggroup.org>. 17 An implementation of the Trusted Software Stack (TSS), the 18 userspace enablement piece of the specification, can be 19 obtained at: <http://sourceforge.net/projects/trousers>. To 20 compile this driver as a module, choose M here; the module 21 will be called tpm. If unsure, say N. 22 Notes: 23 1) For more TPM drivers enable CONFIG_PNP, CONFIG_ACPI 24 and CONFIG_PNPACPI. 25 2) Without ACPI enabled, the BIOS event log won't be accessible, 26 which is required to validate the PCR 0-7 values. 27 28if TCG_TPM 29 30config TCG_TPM2_HMAC 31 bool "Use HMAC and encrypted transactions on the TPM bus" 32 default y 33 select CRYPTO_LIB_SHA256 34 help 35 Setting this causes us to deploy a scheme which uses request 36 and response HMACs in addition to encryption for 37 communicating with the TPM to prevent or detect bus snooping 38 and interposer attacks (see tpm-security.rst). Saying Y 39 here adds some encryption overhead to all kernel to TPM 40 transactions. 41 42config HW_RANDOM_TPM 43 bool "TPM HW Random Number Generator support" 44 depends on TCG_TPM && HW_RANDOM && !(TCG_TPM=y && HW_RANDOM=m) 45 default y 46 help 47 This setting exposes the TPM's Random Number Generator as a hwrng 48 device. This allows the kernel to collect randomness from the TPM at 49 boot, and provides the TPM randomines in /dev/hwrng. 50 51 If unsure, say Y. 52 53config TCG_TIS_CORE 54 tristate 55 help 56 TCG TIS TPM core driver. It implements the TPM TCG TIS logic and hooks 57 into the TPM kernel APIs. Physical layers will register against it. 58 59config TCG_TIS 60 tristate "TPM Interface Specification 1.2 Interface / TPM 2.0 FIFO Interface" 61 depends on X86 || OF 62 select TCG_TIS_CORE 63 help 64 If you have a TPM security chip that is compliant with the 65 TCG TIS 1.2 TPM specification (TPM1.2) or the TCG PTP FIFO 66 specification (TPM2.0) say Yes and it will be accessible from 67 within Linux. To compile this driver as a module, choose M here; 68 the module will be called tpm_tis. 69 70config TCG_TIS_SPI 71 tristate "TPM Interface Specification 1.3 Interface / TPM 2.0 FIFO Interface - (SPI)" 72 depends on SPI 73 select TCG_TIS_CORE 74 help 75 If you have a TPM security chip which is connected to a regular, 76 non-tcg SPI master (i.e. most embedded platforms) that is compliant with the 77 TCG TIS 1.3 TPM specification (TPM1.2) or the TCG PTP FIFO 78 specification (TPM2.0) say Yes and it will be accessible from 79 within Linux. To compile this driver as a module, choose M here; 80 the module will be called tpm_tis_spi. 81 82config TCG_TIS_SPI_CR50 83 bool "Cr50 SPI Interface" 84 depends on TCG_TIS_SPI 85 help 86 If you have a H1 secure module running Cr50 firmware on SPI bus, 87 say Yes and it will be accessible from within Linux. 88 89config TCG_TIS_I2C 90 tristate "TPM Interface Specification 1.3 Interface / TPM 2.0 FIFO Interface - (I2C - generic)" 91 depends on I2C 92 select CRC_CCITT 93 select TCG_TIS_CORE 94 help 95 If you have a TPM security chip, compliant with the TCG TPM PTP 96 (I2C interface) specification and connected to an I2C bus master, 97 say Yes and it will be accessible from within Linux. 98 To compile this driver as a module, choose M here; 99 the module will be called tpm_tis_i2c. 100 101config TCG_TIS_SYNQUACER 102 tristate "TPM Interface Specification 1.2 Interface / TPM 2.0 FIFO Interface (MMIO - SynQuacer)" 103 depends on ARCH_SYNQUACER || COMPILE_TEST 104 select TCG_TIS_CORE 105 help 106 If you have a TPM security chip that is compliant with the 107 TCG TIS 1.2 TPM specification (TPM1.2) or the TCG PTP FIFO 108 specification (TPM2.0) say Yes and it will be accessible from 109 within Linux on Socionext SynQuacer platform. 110 To compile this driver as a module, choose M here; 111 the module will be called tpm_tis_synquacer. 112 113config TCG_TIS_I2C_CR50 114 tristate "TPM Interface Specification 2.0 Interface (I2C - CR50)" 115 depends on I2C 116 help 117 This is a driver for the Google cr50 I2C TPM interface which is a 118 custom microcontroller and requires a custom i2c protocol interface 119 to handle the limitations of the hardware. To compile this driver 120 as a module, choose M here; the module will be called tcg_tis_i2c_cr50. 121 122config TCG_TIS_I2C_ATMEL 123 tristate "TPM Interface Specification 1.2 Interface (I2C - Atmel)" 124 depends on I2C 125 help 126 If you have an Atmel I2C TPM security chip say Yes and it will be 127 accessible from within Linux. 128 To compile this driver as a module, choose M here; the module will 129 be called tpm_tis_i2c_atmel. 130 131config TCG_TIS_I2C_INFINEON 132 tristate "TPM Interface Specification 1.2 Interface (I2C - Infineon)" 133 depends on I2C 134 help 135 If you have a TPM security chip that is compliant with the 136 TCG TIS 1.2 TPM specification and Infineon's I2C Protocol Stack 137 Specification 0.20 say Yes and it will be accessible from within 138 Linux. 139 To compile this driver as a module, choose M here; the module 140 will be called tpm_i2c_infineon. 141 142config TCG_TIS_I2C_NUVOTON 143 tristate "TPM Interface Specification 1.2 Interface (I2C - Nuvoton)" 144 depends on I2C 145 help 146 If you have a TPM security chip with an I2C interface from 147 Nuvoton Technology Corp. say Yes and it will be accessible 148 from within Linux. 149 To compile this driver as a module, choose M here; the module 150 will be called tpm_i2c_nuvoton. 151 152config TCG_NSC 153 tristate "National Semiconductor TPM Interface" 154 depends on X86 155 help 156 If you have a TPM security chip from National Semiconductor 157 say Yes and it will be accessible from within Linux. To 158 compile this driver as a module, choose M here; the module 159 will be called tpm_nsc. 160 161config TCG_ATMEL 162 tristate "Atmel TPM Interface" 163 depends on PPC64 || HAS_IOPORT_MAP 164 depends on HAS_IOPORT 165 help 166 If you have a TPM security chip from Atmel say Yes and it 167 will be accessible from within Linux. To compile this driver 168 as a module, choose M here; the module will be called tpm_atmel. 169 170config TCG_INFINEON 171 tristate "Infineon Technologies TPM Interface" 172 depends on PNP || COMPILE_TEST 173 help 174 If you have a TPM security chip from Infineon Technologies 175 (either SLD 9630 TT 1.1 or SLB 9635 TT 1.2) say Yes and it 176 will be accessible from within Linux. 177 To compile this driver as a module, choose M here; the module 178 will be called tpm_infineon. 179 Further information on this driver and the supported hardware 180 can be found at http://www.trust.rub.de/projects/linux-device-driver-infineon-tpm/ 181 182config TCG_IBMVTPM 183 tristate "IBM VTPM Interface" 184 depends on PPC_PSERIES 185 help 186 If you have IBM virtual TPM (VTPM) support say Yes and it 187 will be accessible from within Linux. To compile this driver 188 as a module, choose M here; the module will be called tpm_ibmvtpm. 189 190config TCG_XEN 191 tristate "XEN TPM Interface" 192 depends on TCG_TPM && XEN 193 select XEN_XENBUS_FRONTEND 194 help 195 If you want to make TPM support available to a Xen user domain, 196 say Yes and it will be accessible from within Linux. See 197 the manpages for xl, xl.conf, and docs/misc/vtpm.txt in 198 the Xen source repository for more details. 199 To compile this driver as a module, choose M here; the module 200 will be called xen-tpmfront. 201 202config TCG_CRB 203 tristate "TPM 2.0 CRB Interface" 204 depends on ACPI 205 help 206 If you have a TPM security chip that is compliant with the 207 TCG CRB 2.0 TPM specification say Yes and it will be accessible 208 from within Linux. To compile this driver as a module, choose 209 M here; the module will be called tpm_crb. 210 211config TCG_VTPM_PROXY 212 tristate "VTPM Proxy Interface" 213 depends on TCG_TPM 214 help 215 This driver proxies for an emulated TPM (vTPM) running in userspace. 216 A device /dev/vtpmx is provided that creates a device pair 217 /dev/vtpmX and a server-side file descriptor on which the vTPM 218 can receive commands. 219 220config TCG_FTPM_TEE 221 tristate "TEE based fTPM Interface" 222 depends on TEE && OPTEE 223 help 224 This driver proxies for firmware TPM running in TEE. 225 226source "drivers/char/tpm/st33zp24/Kconfig" 227endif # TCG_TPM 228