[tpm2] Re: tpm2_createprimary to a transient handle...

Kenneth Goldman <kgoldman at us.ibm.com>
Newsgroups dev.linux.lists.tpm2
Message-ID < <BN8PR15MB275357232C1193527DC86BCDF2089@BN8PR15MB2753.namprd15.prod.outlook.com>>
This is written up in part 1.  In general, …


  1.  You can't encrypt an x509 certificate with an asymmetric key.  It's too large.
  2.  The CA does not want to issue the certificate and not know wether the receiver can decrypt it.
  3.  A more typical approach is make credential / activate credential where what is activated is a challenge. The activator returns the challenge to the CA and then the CA returns the certificate.
  4.  YMMV.

From: Sievert, James <james.sievert(a)bsci.com>
Sent: Sunday, March 6, 2022 8:03 AM
To: tpm2(a)lists.01.org
Subject: [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...

To summarize my situation, I’d like a _simple_ infrastructure for providing certs to my platform through commonly available software, namely OpenSSL.  The “proof” for cert. platform provisioning is the EK cert. that comes from the platform TPM manufacturer.   The first attempt was to sign the platform CSRs using the EK cert. as per Section 2.1.2.2 of TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)<https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf>.  Because the EK can only decrypt, this ended up being a dead end.

The second attempt is to accept the CSRs at the server and to encrypt the platform certs. with the EK cert. using OpenSSL CMS.  In this way, only the true platform having the TPM corresponding to the EK cert. could decrypt and provision the certs.  This is what I did:

On the server:
openssl cms -encrypt -in certs.tgz -out certs.tgz.pk7 -recip ek.pem

On the platform:
tpm2_createek -G ecc -c ek.ctx -u ek.pub
tpm2_evictcontrol -c ek.ctx -C o
persistent-handle: 0x81000000
action: persisted

So far, so good.  Now for the problem:
openssl cms -decrypt -in certs.tgz.pk7 -out certs.tgz -inkey 0x81000000 -keyform engine -engine tpm2tss -recip ek.pem
engine "tpm2tss" set.
Enter password for user key:
Error decrypting CMS using private key
140718256973632:error:1010107D:elliptic curve routines:ecdh_simple_compute_key:missing private key:../crypto/ec/ecdh_ossl.c:61:

This is basically implying that tpm2_evictcontrol doesn’t load the private portion of the EK.  Is this correct?

From: Sievert, James
Sent: Friday, March 4, 2022 10:21 AM
To: tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: RE: tpm2_createprimary to a transient handle...


Ø  I'll see if I can get the spec fixed.

Section 2.1.2.2 represents a valid use case, at least in my situation.  It’s not clear to me how this section would be fixed other than removing it.  How exactly should one approach vetting CSRs based on TPM certificates known to a server as per “This is intended to facilitate establishment of further TPM keys, like Device Identification keys, without the need for an Attestation Key. This allows for simpler infrastructure implementations.”  Emphasis intended.  😊

From: Kenneth Goldman <kgoldman(a)us.ibm.com<mailto:kgoldman(a)us.ibm.com>>
Sent: Friday, March 4, 2022 10:04 AM
To: Sievert, James <james.sievert(a)bsci.com<mailto:james.sievert(a)bsci.com>>; tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: {External} RE: tpm2_createprimary to a transient handle...



Thanks for pointing that out.  I'll see if I can get the spec fixed.

There's nothing to stop you from creating a signing primary key in the endorsement hierarchy.  However, 'the EK', the one that has a certificate from the TPM vendor, is not a signing key.

From: Sievert, James <james.sievert(a)bsci.com<mailto:james.sievert(a)bsci.com>>
Sent: Friday, March 4, 2022 8:51 AM
To: tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...


Ø  However, the EK is not a signing key.  It cannot sign anything.

Section 2.1.2.2 of TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)<https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf> contradicts your statement:

“For such platforms, privacy is not a central concern and unique identification is of critical importance. These platforms MAY use a certified EK for signing operations.”

From: Kenneth Goldman <kgoldman(a)us.ibm.com<mailto:kgoldman(a)us.ibm.com>>
Sent: Friday, March 4, 2022 8:31 AM
To: Sievert, James <james.sievert(a)bsci.com<mailto:james.sievert(a)bsci.com>>; tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
Subject: {External} RE: tpm2_createprimary to a transient handle...

In general (not the command line tools), the create primary result stays loaded.

However, the EK is not a signing key.  It cannot sign anything.
attachment.htm (text/html, 20.5 KB)
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"Segoe UI Emoji";
	panose-1:2 11 5 2 4 2 4 2 2 3;}
@font-face
	{font-family:"DejaVu Sans";
	panose-1:2 11 6 3 3 8 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"DejaVu Sans",sans-serif;
	color:windowtext;
	font-weight:normal;
	font-style:normal;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:522787566;
	mso-list-type:hybrid;
	mso-list-template-ids:1837270994 1223731300 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-start-at:2;
	mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l1
	{mso-list-id:995958555;
	mso-list-type:hybrid;
	mso-list-template-ids:-1518055268 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l1:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l2
	{mso-list-id:1256093150;
	mso-list-type:hybrid;
	mso-list-template-ids:-1984284272 -237612856 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l2:level1
	{mso-level-start-at:2;
	mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l2:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l2:level3
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l2:level4
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l2:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l2:level6
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l2:level7
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
@list l2:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Courier New";}
@list l2:level9
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Wingdings;}
@list l3
	{mso-list-id:1428115017;
	mso-list-template-ids:219951062;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level2
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level3
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level4
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level5
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level6
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level7
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level8
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3:level9
	{mso-level-number-format:bullet;
	mso-level-text:;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">This is written up in part 1.&nbsp; In general, …<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<ol style="margin-top:0in" start="1" type="1">
<li class="MsoListParagraph" style="margin-left:0in;mso-list:l1 level1 lfo6"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">You can't encrypt an x509 certificate with an asymmetric key.&nbsp; It's too large.<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0in;mso-list:l1 level1 lfo6"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">The CA does not want to issue the certificate and not know wether the receiver can decrypt it.<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0in;mso-list:l1 level1 lfo6"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">A more typical approach is make credential / activate credential where what is activated is a challenge. The activator returns the
 challenge to the CA and then the CA returns the certificate. <o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0in;mso-list:l1 level1 lfo6"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">YMMV.<o:p></o:p></span></li></ol>
<p class="MsoNormal"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Sievert, James &lt;[email protected]&gt;
<br>
<b>Sent:</b> Sunday, March 6, 2022 8:03 AM<br>
<b>To:</b> [email protected]<br>
<b>Subject:</b> [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">To summarize my situation, I’d like a _<i>simple</i>_ infrastructure for providing certs to my platform through commonly available software, namely OpenSSL.&nbsp; The “proof” for cert. platform provisioning is the EK
 cert. that comes from the platform TPM manufacturer.&nbsp; &nbsp;The first attempt was to sign the platform CSRs using the EK cert. as per Section 2.1.2.2 of
<a href="https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf">TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)</a>.&nbsp; Because the EK can only decrypt, this ended up being a dead end.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The second attempt is to accept the CSRs at the server and to encrypt the platform certs. with the EK cert. using OpenSSL CMS.&nbsp; In this way, only the true platform having the TPM corresponding to the EK cert. could
 decrypt and provision the certs.&nbsp; This is what I did:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">On the server:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">openssl cms -encrypt -in certs.tgz -out certs.tgz.pk7 -recip ek.pem<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">On the platform:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">tpm2_createek -G ecc -c ek.ctx -u ek.pub<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">tpm2_evictcontrol -c ek.ctx -C o<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">persistent-handle: 0x81000000<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">action: persisted<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">So far, so good.&nbsp; Now for the problem:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">openssl cms -decrypt -in certs.tgz.pk7 -out certs.tgz -inkey 0x81000000 -keyform engine -engine tpm2tss -recip ek.pem<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">engine &quot;tpm2tss&quot; set.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">Enter password for user key:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">Error decrypting CMS using private key<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><span style="font-size:8.0pt;font-family:&quot;Courier New&quot;">140718256973632:error:1010107D:elliptic curve routines:ecdh_simple_compute_key:missing private key:../crypto/ec/ecdh_ossl.c:61:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">This is basically implying that tpm2_evictcontrol doesn’t load the private portion of the EK.&nbsp; Is this correct?<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Sievert, James <br>
<b>Sent:</b> Friday, March 4, 2022 10:21 AM<br>
<b>To:</b> <a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> RE: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoListParagraph" style="margin-left:1.0in;text-indent:-.25in;mso-list:l0 level1 lfo3">
<![if !supportLists]><span style="font-family:Wingdings"><span style="mso-list:Ignore">Ø<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;
</span></span></span><![endif]><b>I'll see if I can get the spec fixed.<o:p></o:p></b></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Section 2.1.2.2 represents a valid use case, at least in my situation.&nbsp; It’s not clear to me how this section would be fixed other than removing it.&nbsp; How exactly should one approach vetting CSRs based on TPM certificates
 known to a server as per “This is intended to facilitate establishment of further TPM keys, like Device Identification keys, without the need for an Attestation Key.
<b>This allows for simpler infrastructure implementations.</b>”&nbsp; Emphasis intended.&nbsp;
<span style="font-family:&quot;Segoe UI Emoji&quot;,sans-serif">&#128522;</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Kenneth Goldman &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Friday, March 4, 2022 10:04 AM<br>
<b>To:</b> Sievert, James &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;;
<a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> {External} RE: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.0in"><b>Thanks for pointing that out.&nbsp; I'll see if I can get the spec fixed.<o:p></o:p></b></p>
<p class="MsoNormal" style="margin-left:1.0in"><b><o:p>&nbsp;</o:p></b></p>
<p class="MsoNormal" style="margin-left:1.0in"><b>There's nothing to stop you from creating a signing primary key in the endorsement hierarchy.&nbsp; However, 'the EK', the one that has a certificate from the TPM vendor, is not a signing key.<o:p></o:p></b></p>
<p class="MsoNormal" style="margin-left:1.0in"><b><o:p>&nbsp;</o:p></b></p>
<p class="MsoNormal" style="margin-left:1.0in"><b>From:</b> Sievert, James &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Friday, March 4, 2022 8:51 AM<br>
<b>To:</b> <a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> [EXTERNAL] [tpm2] Re: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><o:p>&nbsp;</o:p></p>
<p class="MsoListParagraph" style="margin-left:1.5in;text-indent:-.25in;mso-list:l2 level1 lfo5">
<![if !supportLists]><span style="font-family:Wingdings"><span style="mso-list:Ignore">Ø<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;
</span></span></span><![endif]><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">However, the EK is not a signing key.&nbsp; It cannot sign anything.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">Section 2.1.2.2 of <a href="https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_EKCredentialProfile_v2p4_r3.pdf">TCG Credential Profile EK 2.0 (trustedcomputinggroup.org)</a> contradicts your statement:<br>
<br>
“For such platforms, privacy is not a central concern and unique identification is of critical importance. These platforms MAY use a certified EK for signing operations.”<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p>&nbsp;</o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:1.0in"><b>From:</b> Kenneth Goldman &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Friday, March 4, 2022 8:31 AM<br>
<b>To:</b> Sievert, James &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;;
<a href="mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> {External} RE: tpm2_createprimary to a transient handle...<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">In general (not the command line tools), the create primary result stays loaded.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif">However, the EK is not a signing key.&nbsp; It cannot sign anything.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-family:&quot;DejaVu Sans&quot;,sans-serif"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.