[tpm2] Re: tpm2_createprimary to a transient handle...

Sievert, James <james.sievert at bsci.com>
Newsgroups dev.linux.lists.tpm2
Message-ID < <DS7PR03MB5576563527FDBC50719A02E19A059@DS7PR03MB5576.namprd03.prod.outlook.com>>
  *   I'll see if I can get the spec fixed.

Section 2.1.2.2 represents a valid use case, at least in my situation.  It’s not clear to me how this section would be fixed other than removing it.  How exactly should one approach vetting CSRs based on TPM certificates known to a server as per “This is intended to facilitate establishment of further TPM keys, like Device Identification keys, without the need for an Attestation Key. This allows for simpler infrastructure implementations.”  Emphasis intended.  😊

From: Kenneth Goldman <kgoldman(a)us.ibm.com>
Sent: Friday, March 4, 2022 10:04 AM
To: Sievert, James <james.sievert(a)bsci.com>; tpm2(a)lists.01.org
Subject: {External} RE: tpm2_createprimary to a transient handle...



Thanks for pointing that out.  I'll see if I can get the spec fixed.

There's nothing to stop you from creating a signing primary key in the endorsement hierarchy.  However, 'the EK', the one that has a certificate from the TPM vendor, is not a signing key.

From: Sievert, James <james.sievert(a)bsci.com<mailto:james.sievert(a)bsci.com>>
Sent: Friday, March 4, 2022 8:51 AM
To: tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...


Ø  However, the EK is not a signing key.  It cannot sign anything.

Section 2.1.2.2 of TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)<https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf> contradicts your statement:

“For such platforms, privacy is not a central concern and unique identification is of critical importance. These platforms MAY use a certified EK for signing operations.”

From: Kenneth Goldman <kgoldman(a)us.ibm.com<mailto:kgoldman(a)us.ibm.com>>
Sent: Friday, March 4, 2022 8:31 AM
To: Sievert, James <james.sievert(a)bsci.com<mailto:james.sievert(a)bsci.com>>; tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: {External} RE: tpm2_createprimary to a transient handle...

In general (not the command line tools), the create primary result stays loaded.

However, the EK is not a signing key.  It cannot sign anything.
attachment.htm (text/html, 10.3 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"DejaVu Sans";}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle22
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:522787566;
	mso-list-type:hybrid;
	mso-list-template-ids:1837270994 1223731300 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-start-at:2;
	mso-level-number-format:bullet;
	mso-level-text:\F0D8;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1
	{mso-list-id:1256093150;
	mso-list-type:hybrid;
	mso-list-template-ids:-1984284272 -237612856 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l1:level1
	{mso-level-start-at:2;
	mso-level-number-format:bullet;
	mso-level-text:\F0D8;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l1:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l1:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l1:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l1:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<ul style="margin-top:0in" type="disc">
<li class="MsoListParagraph" style="margin-left:0in;mso-list:l0 level1 lfo3"><b>I'll see if I can get the spec fixed.<o:p></o:p></b></li></ul>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Section 2.1.2.2 represents a valid use case, at least in my situation.&nbsp; It’s not clear to me how this section would be fixed other than removing it.&nbsp; How exactly should one approach vetting CSRs based on TPM certificates known to a server
 as per “This is intended to facilitate establishment of further TPM keys, like Device Identification keys, without the need for an Attestation Key.
<b>This allows for simpler infrastructure implementations.</b>”&nbsp; Emphasis intended.&nbsp;
<span style="font-family:&quot;Segoe UI Emoji&quot;,sans-serif">😊</span><o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> Kenneth Goldman &lt;[email protected]&gt; <br>
<b>Sent:</b> Friday, March 4, 2022 10:04 AM<br>
<b>To:</b> Sievert, James &lt;[email protected]&gt;; [email protected]<br>
<b>Subject:</b> {External} RE: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><span style="font-family:&quot;DejaVu Sans&quot;"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;DejaVu Sans&quot;"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>Thanks for pointing that out.&nbsp; I'll see if I can get the spec fixed.<o:p></o:p></b></p>
<p class="MsoNormal" style="margin-left:.5in"><b><o:p>&nbsp;</o:p></b></p>
<p class="MsoNormal" style="margin-left:.5in"><b>There's nothing to stop you from creating a signing primary key in the endorsement hierarchy.&nbsp; However, 'the EK', the one that has a certificate from the TPM vendor, is not a signing key.<o:p></o:p></b></p>
<p class="MsoNormal" style="margin-left:.5in"><b><o:p>&nbsp;</o:p></b></p>
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Sievert, James &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Friday, March 4, 2022 8:51 AM<br>
<b>To:</b> <a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoListParagraph" style="margin-left:1.0in;text-indent:-.25in;mso-list:l1 level1 lfo2">
<![if !supportLists]><span style="font-family:Wingdings"><span style="mso-list:Ignore">Ø<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;
</span></span></span><![endif]><span style="font-family:&quot;DejaVu Sans&quot;">However, the EK is not a signing key.&nbsp; It cannot sign anything.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Section 2.1.2.2 of <a href="https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf">
TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)</a> contradicts your statement:<br>
<br>
“For such platforms, privacy is not a central concern and unique identification is of critical importance. These platforms MAY use a certified EK for signing operations.”<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Kenneth Goldman &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Friday, March 4, 2022 8:31 AM<br>
<b>To:</b> Sievert, James &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;;
<a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> {External} RE: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;">In general (not the command line tools), the create primary result stays loaded.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;">However, the EK is not a signing key.&nbsp; It cannot sign anything.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.