- Category
- Cybersecurity
- Rank
- No. 3201Tools index
- Pricing
- Open Source
- Type
- TOOL
- Date
About
tpmlsm is an eBPF-based Linux kernel guard that lets only allowlisted binaries open the TPM devices /dev/tpm0 and /dev/tpmrm0. By default, any root process or member of the tss group can open them and use TPM-protected keys, such as mTLS private keys. Allowed binaries are identified by path and SHA-256 hash, so modifying or copying a file removes it from the list. The author describes it as a prototype.
Tags
ebpftpmlinuxbpf-lsmsecurityvtpm
Tech Stack
Go
Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.