[tpm2] Re: Clearing TPM

accounts <burnsds.accounts at protonmail.com> Wed, 05 Oct 2022 16:45:05 +0000
Newsgroups dev.linux.lists.tpm2
Message-ID <P3_eYbMn-8swpMxU6oR12IjAFam7WKJt1zXpL9u_Is6qnKj_RtxmTRcpXHqORzzTZWg-nATbDAsJLAn-Wu4-H58jpVMcfvB4sKYyvsw2hpw=@protonmail.com>
Wow this is really helpful. Do you know if the request values are vendor specific? It would be nice to know what the different values mean.

Thanks,
Dan

------- Original Message -------
On Friday, September 30th, 2022 at 4:07 PM, Steven Clark <davolfman(a)gmail.com> wrote:

> Also there's the Physical Presence Interface if your device supports it. You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's platform authority to issue a clear, usually after prompting you to press some key to indicate you're at the console and agree.
>
> For example:
> $echo 5 > /sys/class/tpm/tpm0/ppi/request
> $reboot
>
> On Fri, Sep 30, 2022, 12:50 PM Roberts, William C <william.c.roberts(a)intel.com> wrote:
>
>> On Fri, 2022-09-30 at 17:46 +0000, burnsds.accounts(a)protonmail.com
>> wrote:
>>> Is there any way to get out of this state without the lockout
>>> password?
>>
>> Platform auth, which you won't have as its typically randomly set by
>> the OS on boot or you can use the bios settings to clear an Intel or
>> AMD based TPM. For discrete TPMs you need to consult their manuals.
>> Typically, its playing with some jumpers.
>>
>>> _______________________________________________
>>> tpm2 mailing list -- tpm2(a)lists.01.org
>>> To unsubscribe send an email to tpm2-leave(a)lists.01.org
>>> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
>> _______________________________________________
>> tpm2 mailing list -- tpm2(a)lists.01.org
>> To unsubscribe send an email to tpm2-leave(a)lists.01.org
>> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm (text/html, 3 KB)
<div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);">Wow this is really helpful.&nbsp; Do you know if the request values are vendor specific?&nbsp; It would be nice to know what the different values mean.</div><div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);"><br>Thanks,<br>Dan</div><div style="font-family: Arial; font-size: 14px; color: rgb(0, 0, 0);"><br></div><div class="protonmail_quote">
        ------- Original Message -------<br>
        On Friday, September 30th, 2022 at 4:07 PM, Steven Clark &lt;[email protected]&gt; wrote:<br><br>
        <blockquote class="protonmail_quote" type="cite">
            <div dir="auto">Also there's the Physical Presence Interface if your device supports it.  You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot.  The BIOS then uses it's platform authority to issue a clear, usually after prompting you to press some key to indicate you're at the console and agree.<div dir="auto"><br></div><div dir="auto">For example:</div><div dir="auto">$echo 5 &gt; /sys/class/tpm/tpm0/ppi/request</div><div dir="auto">$reboot</div></div><br><div class="gmail_quote"><div class="gmail_attr" dir="ltr">On Fri, Sep 30, 2022, 12:50 PM Roberts, William C &lt;<a href="mailto:[email protected]" rel="noreferrer nofollow noopener" target="_blank">[email protected]</a>&gt; wrote:<br></div><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex" class="gmail_quote">On Fri, 2022-09-30 at 17:46 +0000, <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
wrote:<br>
&gt; Is there any way to get out of this state without the lockout<br>
&gt; password?<br>
<br>
Platform auth, which you won't have as its typically randomly set by<br>
the OS on boot or you can use the bios settings to clear an Intel or<br>
AMD based TPM. For discrete TPMs you need to consult their manuals.<br>
Typically, its playing with some jumpers. <br>
<br>
&gt; _______________________________________________<br>
&gt; tpm2 mailing list -- <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
&gt; To unsubscribe send an email to <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
&gt; %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
_______________________________________________<br>
tpm2 mailing list -- <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
To unsubscribe send an email to <a rel="noreferrer nofollow noopener" target="_blank" href="mailto:[email protected]">[email protected]</a><br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
</blockquote></div>

        </blockquote><br>
    </div>