[tpm2] Re: Clearing TPM
accounts <burnsds.accounts at protonmail.com> Wed, 05 Oct 2022 16:45:05 +0000
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <P3_eYbMn-8swpMxU6oR12IjAFam7WKJt1zXpL9u_Is6qnKj_RtxmTRcpXHqORzzTZWg-nATbDAsJLAn-Wu4-H58jpVMcfvB4sKYyvsw2hpw=@protonmail.com> |
Wow this is really helpful. Do you know if the request values are vendor specific? It would be nice to know what the different values mean. Thanks, Dan ------- Original Message ------- On Friday, September 30th, 2022 at 4:07 PM, Steven Clark <davolfman(a)gmail.com> wrote: > Also there's the Physical Presence Interface if your device supports it. You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's platform authority to issue a clear, usually after prompting you to press some key to indicate you're at the console and agree. > > For example: > $echo 5 > /sys/class/tpm/tpm0/ppi/request > $reboot > > On Fri, Sep 30, 2022, 12:50 PM Roberts, William C <william.c.roberts(a)intel.com> wrote: > >> On Fri, 2022-09-30 at 17:46 +0000, burnsds.accounts(a)protonmail.com >> wrote: >>> Is there any way to get out of this state without the lockout >>> password? >> >> Platform auth, which you won't have as its typically randomly set by >> the OS on boot or you can use the bios settings to clear an Intel or >> AMD based TPM. For discrete TPMs you need to consult their manuals. >> Typically, its playing with some jumpers. >> >>> _______________________________________________ >>> tpm2 mailing list -- tpm2(a)lists.01.org >>> To unsubscribe send an email to tpm2-leave(a)lists.01.org >>> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s >> _______________________________________________ >> tpm2 mailing list -- tpm2(a)lists.01.org >> To unsubscribe send an email to tpm2-leave(a)lists.01.org >> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm
(text/html, 3 KB)
<div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);">Wow this is really helpful. Do you know if the request values are vendor specific? It would be nice to know what the different values mean.</div><div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);"><br>Thanks,<br>Dan</div><div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);"><br></div><div class="protonmail_quote">
------- Original Message -------<br>
On Friday, September 30th, 2022 at 4:07 PM, Steven Clark <[email protected]> wrote:<br><br>
<blockquote class="protonmail_quote" type="cite">
<div dir="auto">Also there's the Physical Presence Interface if your device supports it. You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's platform authority to issue a clear, usually after prompting you to press some key to indicate you're at the console and agree.<div dir="auto"><br></div><div dir="auto">For example:</div><div dir="auto">$echo 5 > /sys/class/tpm/tpm0/ppi/request</div><div dir="auto">$reboot</div></div><br><div class="gmail_quote"><div class="gmail_attr" dir="ltr">On Fri, Sep 30, 2022, 12:50 PM Roberts, William C <<a href="mailto:[email protected]" rel="noreferrer nofollow noopener" target="_blank">[email protected]</a>> wrote:<br></div><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex" class="gmail_quote">On Fri, 2022-09-30 at 17:46 +0000, <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
wrote:<br>
> Is there any way to get out of this state without the lockout<br>
> password?<br>
<br>
Platform auth, which you won't have as its typically randomly set by<br>
the OS on boot or you can use the bios settings to clear an Intel or<br>
AMD based TPM. For discrete TPMs you need to consult their manuals.<br>
Typically, its playing with some jumpers. <br>
<br>
> _______________________________________________<br>
> tpm2 mailing list -- <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
> To unsubscribe send an email to <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
_______________________________________________<br>
tpm2 mailing list -- <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
To unsubscribe send an email to <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
</blockquote></div>
</blockquote><br>
</div>