2022-07-15 13:19:45 +00:00
|
|
|
Index: rust-keylime-0.1.0+git.1657303637.5b9072a/keylime.conf
|
2021-11-25 15:22:45 +00:00
|
|
|
===================================================================
|
2022-07-15 13:19:45 +00:00
|
|
|
--- rust-keylime-0.1.0+git.1657303637.5b9072a.orig/keylime.conf
|
|
|
|
+++ rust-keylime-0.1.0+git.1657303637.5b9072a/keylime.conf
|
2021-11-19 13:51:44 +00:00
|
|
|
@@ -4,7 +4,8 @@
|
2021-07-28 13:39:06 +00:00
|
|
|
|
2021-11-19 13:51:44 +00:00
|
|
|
# Revocation IP & Port used by either the cloud_agent or keylime_ca to receive
|
|
|
|
# revocation events from the verifier.
|
|
|
|
-receive_revocation_ip = 127.0.0.1
|
|
|
|
+# receive_revocation_ip = 127.0.0.1
|
|
|
|
+receive_revocation_ip = <REMOTE_IP>
|
|
|
|
receive_revocation_port = 8992
|
|
|
|
|
|
|
|
|
|
|
|
@@ -13,7 +14,8 @@ receive_revocation_port = 8992
|
2021-07-28 13:39:06 +00:00
|
|
|
#=============================================================================
|
|
|
|
|
2021-11-19 13:51:44 +00:00
|
|
|
# The binding address and port for the agent server
|
2021-07-28 13:39:06 +00:00
|
|
|
-cloudagent_ip = 127.0.0.1
|
|
|
|
+# cloudagent_ip = 127.0.0.1
|
|
|
|
+cloudagent_ip = 0.0.0.0
|
|
|
|
cloudagent_port = 9002
|
|
|
|
|
2021-11-19 13:51:44 +00:00
|
|
|
# Address and port where the verifier and tenant can connect to reach the agent.
|
|
|
|
@@ -22,7 +24,8 @@ agent_contact_ip = 127.0.0.1
|
|
|
|
agent_contact_port = 9002
|
2021-07-28 13:39:06 +00:00
|
|
|
|
2021-11-19 13:51:44 +00:00
|
|
|
# The address and port of registrar server which agent communicate with
|
2021-07-28 13:39:06 +00:00
|
|
|
-registrar_ip = 127.0.0.1
|
|
|
|
+# registrar_ip = 127.0.0.1
|
2021-11-19 13:51:44 +00:00
|
|
|
+registrar_ip = <REMOTE_IP>
|
2021-07-28 13:39:06 +00:00
|
|
|
registrar_port = 8890
|
|
|
|
|
2022-06-14 11:50:32 +00:00
|
|
|
# The keylime working directory. Can be overriden by setting the KEYLIME_DIR
|
2022-07-15 13:19:45 +00:00
|
|
|
@@ -127,3 +130,21 @@ tpm_signing_alg = rsassa
|
|
|
|
# handle (e.g. "0x81000000"). The Keylime agent will then not attempt to
|
|
|
|
# create a new EK upon startup, and neither will it flush the EK upon exit.
|
|
|
|
ek_handle = generate
|
|
|
|
+
|
|
|
|
+# The user account to switch to to drop privileges when started as root
|
|
|
|
+# If left empty, the agent will keep running with high privileges.
|
|
|
|
+# The user and group specified here must allow the user to access the
|
|
|
|
+# WORK_DIR (typically /var/lib/keylime) and /dev/tpmrm0. Therefore,
|
|
|
|
+# suggested value for the run_as parameter is keylime:tss.
|
|
|
|
+# The following commands should be used to set ownership before running the
|
|
|
|
+# agent:
|
|
|
|
+# chown keylime /var/lib/keylime
|
|
|
|
+#
|
|
|
|
+# If agent_data.json already exists:
|
|
|
|
+# chown keylime /var/lib/keylime/agent_data.json
|
|
|
|
+#
|
|
|
|
+# If cv_ca directory exists:
|
|
|
|
+# chown keylime /var/lib/keylime/cv_ca
|
|
|
|
+# chown keylime /var/lib/keylime/cv_ca/cacert.crt
|
|
|
|
+#
|
|
|
|
+run_as = keylime:tss
|