[tpm2] Re: Help - how to store a certificate in the NV under the platform hierarchy?

Fuchs, Andreas <andreas.fuchs at sit.fraunhofer.de>
Newsgroups dev.linux.lists.tpm2
Message-ID <AS8P194MB1669E8D2E9D32D5DBC0268A3A6369@AS8P194MB1669.EURP194.PROD.OUTLOOK.COM>
Ok, I guess you are using swtpm_bios, right ?

In that case the BIOS behavior is simulated, including setting the PH password.

You want to pass -u to swtpm_bios to keep PH open:
https://github.com/stefanberger/swtpm/blob/master/man/man8/swtpm_bios.pod

________________________________________
Von: arlotito(a)microsoft.com <arlotito(a)microsoft.com>
Gesendet: Donnerstag, 17. Februar 2022 11:21
An: tpm2(a)lists.01.org
Betreff: [tpm2] Re: Help - how to store a certificate in the NV under the platform hierarchy?

hmm, interesting...

I tried the same command on a RPI4 with a physical TPM (Infineon SLB9670)... and it worked.

tpm2_nvdefine 0x01C90000 -C p -s 898 -a "ppread|ppwrite|platformcreate"

and this is what I get:
nv-index: 0x1c90000

Maybe, as you commented, it could be a specific issue of the ibm swtpm (v1661).

I'll keep on working on both (swtpm and rpi4/slb9670)

Thanks!
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org
To unsubscribe send an email to tpm2-leave(a)lists.01.org
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.