[tpm2] Re: Re-provision TPM
at rubynerd <x at rubynerd.net>
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <CAFmPt0qQbjL+Wd0HOUJ1O50GtGNErBgdAx_VZOt+7yCt7SxXLg@mail.gmail.com> |
Hi Anthony, I'm also new to the tpm2-tools project, and whilst I cannot advise on most of the asks in your email, I can confirm the tpm2_takeownership command was changed to tpm2_changeauth, which offers similar functionality. Further information is available in the changelog: https://github.com/tpm2-software/tpm2-tools/blame/master/doc/CHANGELOG.md#L867-L872 There's quite a bit of movement between what's currently in source control and the snippets floating around on StackOverflow, the changelog is a really good resource for reconciling these. One thing to note: if you're building this from source, the commands have changed from "tpm2_commandname" to "tpm2 commandname", which was another pitfall I fell into during my explorations. Regarding the specifics of EKs and the differences/functionality of the APIs themselves, I'm afraid I'm woefully out of my depth! Hope this helps, Luke On Wed, Jun 30, 2021 at 11:07 AM Anthony Arrascue <AArrascue(a)neuroloop.de> wrote: > A way of re-provisioning (on a different OS image) that worked for me is > the following: > > > > *tpm2_startup* > > #This clears the persistent storage > > *tpm2_clear* > > #To change profile from ECC to RSA > > *sed -i 's/"profile_name": "P_ECCP256SHA256"/"profile_name": > "P_RSA2048SHA256"/g' /usr/local/etc/tpm2-tss/fapi-config.json* > > #Delete existing keystores > > *rm -rf ~/.local/share/tpm2-tss/user/keystore* > > *rm -rf /usr/local/var/lib/tpm2-tss/system/keystore* > > #Before we provision we need to generate an EK > > *tpm2_createprimary -C e -g sha256 -G rsa -c endorsementprimary.ctx * > > *tpm2_create -C endorsementprimary.ctx -g sha256 -G rsa -u rsak.pub -r > rsak.priv* > > *tpm2_load -C endorsementprimary.ctx -u rsak.pub -r rsak.priv -n rsak.name > <http://rsak.name> -c rsak.ctx* > > *tpm2_evictcontrol -c rsak.ctx 0x81010001* > > *tss2_provision* > > > > Without the tpm2_createprimary I would get an error when I use > tss2_provision (something like “key cannot be signed”. I cannot remember > the error message, but it contained the word EK). > > > > Some questions that came to my mind: > > 1. Can all of this be done using only Fapi (no tpm2 commands) > 2. Why is generating an EK required for provisioning? (which > documentation describes this step) > 3. Previous versions of the tpm2-tools had also a *tpm2_takeownership*. > What happened with it and how to provision with owner’s authorization? > > > > Thank you very much for your comments. > > Best, > > Anthony > > > > > > > > > > > > *From:* Anthony Arrascue > *Sent:* Tuesday, 1 June 2021 19:18 > *To:* 'tpm2(a)lists.01.org' <tpm2(a)lists.01.org> > *Subject:* Re-provision TPM > > > > Hello, > > > > I am learning about the TSS and TPM techonologies. > I have provisioned the TPM with the default settings, which means I am now > using the ECC profile (P_ECCP256SHA256). > > However, encryption was a requirement I needed to fulfill. I just didn't > know that ECC encryption is currently not supported and now I realize RSA > would be a better fit for me. > > So here is my question: > > - I see there is another profile in > /usr/local/etc/tpm2-tss/fapi-profiles, namely P_RSA2048SHA256.json. Is > there a way I can encrypt using the RSA profile instead of the ECC one? I > tried to re-run tss2_provision, after setting it in fapi-config.json, but > it seems this is not the way to proceed. I get the message that the TPM has > been already provisioned. What is the correct way of "changing" profile? Is > it even possible or do I need to reset the TPM? > > Thank you for your help. > > Anthony Arrascue > > > _______________________________________________ > tpm2 mailing list -- tpm2(a)lists.01.org > To unsubscribe send an email to tpm2-leave(a)lists.01.org > %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm
(text/html, 8.5 KB)
<div dir="ltr">Hi Anthony,<div><br></div><div>I'm also new to the tpm2-tools project, and whilst I cannot advise on most of the asks in your email, I can confirm the tpm2_takeownership command was changed to tpm2_changeauth, which offers similar functionality.</div><div><br></div><div>Further information is available in the changelog: <a href="https://github.com/tpm2-software/tpm2-tools/blame/master/doc/CHANGELOG.md#L867-L872">https://github.com/tpm2-software/tpm2-tools/blame/master/doc/CHANGELOG.md#L867-L872</a></div><div><br></div><div>There's quite a bit of movement between what's currently in source control and the snippets floating around on StackOverflow, the changelog is a really good resource for reconciling these. One thing to note: if you're building this from source, the commands have changed from "tpm2_commandname" to "tpm2 commandname", which was another pitfall I fell into during my explorations.</div><div><br></div><div>Regarding the specifics of EKs and the differences/functionality of the APIs themselves, I'm afraid I'm woefully out of my depth!</div><div><br></div><div>Hope this helps,</div><div>Luke</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jun 30, 2021 at 11:07 AM Anthony Arrascue <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <div lang="en-DE" style="overflow-wrap: break-word;"> <div class="gmail-m_2982244829317484457WordSection1"> <p class="MsoNormal"><span lang="EN-US">A way of re-provisioning (on a different OS image) that worked for me is the following:<u></u><u></u></span></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_startup<u></u><u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US">#This clears the persistent storage<u></u><u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_clear<u></u><u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US">#To change profile from ECC to RSA<u></u><u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US">sed -i 's/"profile_name": "P_ECCP256SHA256"/"profile_name": "P_RSA2048SHA256"/g' /usr/local/etc/tpm2-tss/fapi-config.json<u></u><u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US">#Delete existing keystores<u></u><u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US">rm -rf ~/.local/share/tpm2-tss/user/keystore<u></u><u></u></span></b></p> <p class="MsoNormal"><b><span lang="EN-US">rm -rf /usr/local/var/lib/tpm2-tss/system/keystore<u></u><u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US">#Before we provision we need to generate an EK<u></u><u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_createprimary -C e -g sha256 -G rsa -c endorsementprimary.ctx <u></u><u></u></span></b></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_create -C endorsementprimary.ctx -g sha256 -G rsa -u rsak.pub -r rsak.priv<u></u><u></u></span></b></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_load -C endorsementprimary.ctx -u rsak.pub -r rsak.priv -n <a href="http://rsak.name" target="_blank">rsak.name</a> -c rsak.ctx<u></u><u></u></span></b></p> <p class="MsoNormal"><b><span lang="EN-US">tpm2_evictcontrol -c rsak.ctx 0x81010001<u></u><u></u></span></b></p> <p class="MsoNormal"><b><span lang="EN-US">tss2_provision<u></u><u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US">Without the tpm2_createprimary I would get an error when I use tss2_provision (something like “key cannot be signed”. I cannot remember the error message, but it contained the word EK).<u></u><u></u></span></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US">Some questions that came to my mind: <u></u> <u></u></span></p> <ol style="margin-top:0cm" start="1" type="1"> <li class="gmail-m_2982244829317484457MsoListParagraph" style="margin-left:0cm"><span lang="EN-US">Can all of this be done using only Fapi (no tpm2 commands)<u></u><u></u></span></li><li class="gmail-m_2982244829317484457MsoListParagraph" style="margin-left:0cm"><span lang="EN-US">Why is generating an EK required for provisioning? (which documentation describes this step)<u></u><u></u></span></li><li class="gmail-m_2982244829317484457MsoListParagraph" style="margin-left:0cm"><span lang="EN-US">Previous versions of the tpm2-tools had also a <b>tpm2_takeownership</b>. What happened with it and how to provision with owner’s authorization?<u></u><u></u></span></li></ol> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US">Thank you very much for your comments.<u></u><u></u></span></p> <p class="MsoNormal"><span lang="EN-US">Best,<u></u><u></u></span></p> <p class="MsoNormal"><span lang="EN-US">Anthony<u></u><u></u></span></p> <p class="MsoNormal"><b><span lang="EN-US"><u></u> <u></u></span></b></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <p class="MsoNormal"><span lang="EN-US"><u></u> <u></u></span></p> <div style="border-top:none;border-right:none;border-bottom:none;border-left:1.5pt solid blue;padding:0cm 0cm 0cm 4pt"> <div> <div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0cm 0cm"> <p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> Anthony Arrascue <br> <b>Sent:</b> Tuesday, 1 June 2021 19:18<br> <b>To:</b> '<a href="mailto:[email protected]" target="_blank">[email protected]</a>' <<a href="mailto:[email protected]" target="_blank">[email protected]</a>><br> <b>Subject:</b> Re-provision TPM<u></u><u></u></span></p> </div> </div> <p class="MsoNormal"><u></u> <u></u></p> <p class="MsoNormal"><span lang="DE">Hello,<u></u><u></u></span></p> <p class="MsoNormal"><span lang="DE"><u></u> <u></u></span></p> <p class="MsoNormal" style="margin-bottom:12pt;background:white"><span lang="en-DE" style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:rgb(36,41,46)">I am learning about the TSS and TPM techonologies.<br> I have provisioned the TPM with the default settings, which means I am now using the ECC profile (P_ECCP256SHA256).<u></u><u></u></span></p> <p class="MsoNormal" style="margin-bottom:12pt;background:white"><span lang="en-DE" style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:rgb(36,41,46)">However, encryption was a requirement I needed to fulfill. I just didn't know that ECC encryption is currently not supported and now I realize RSA would be a better fit for me.<u></u><u></u></span></p> <p class="MsoNormal" style="margin-bottom:12pt;background:white"><span lang="en-DE" style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:rgb(36,41,46)">So here is my question:<u></u><u></u></span></p> <ul type="disc"> <li class="MsoNormal" style="color:rgb(36,41,46);background:white"> <span lang="en-DE" style="font-size:10.5pt;font-family:"Segoe UI",sans-serif">I see there is another profile in /usr/local/etc/tpm2-tss/fapi-profiles, namely P_RSA2048SHA256.json. Is there a way I can encrypt using the RSA profile instead of the ECC one? I tried to re-run tss2_provision, after setting it in fapi-config.json, but it seems this is not the way to proceed. I get the message that the TPM has been already provisioned. What is the correct way of "changing" profile? Is it even possible or do I need to reset the TPM?<u></u><u></u></span></li></ul> <p class="MsoNormal" style="background:white"><span lang="en-DE" style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:rgb(36,41,46)">Thank you for your help.</span><span lang="en-DE"><u></u><u></u></span></p> <p class="MsoNormal"><span lang="DE" style="font-size:10pt;color:black">Anthony Arrascue<u></u><u></u></span></p> <p class="MsoNormal"><span lang="en-DE"><u></u> <u></u></span></p> </div> </div> </div> _______________________________________________<br> tpm2 mailing list -- <a href="mailto:[email protected]" target="_blank">[email protected]</a><br> To unsubscribe send an email to <a href="mailto:[email protected]" target="_blank">[email protected]</a><br> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</blockquote></div>