[tpm2] Re: Clearing TPM

Steven Clark <davolfman at gmail.com> Wed, 05 Oct 2022 11:47:10 -0700
Newsgroups dev.linux.lists.tpm2
Message-ID <CAOCvsS=XKSPqPtO7RtvP-Zn67nbV84OtoALOLcbCmzETYidUFw@mail.gmail.com>
The codes are defined in Table 2 of the document "TCG PC Client Platform
Physical Presence Interface Specification" which you can find on the
Trusted Computing Group website.   5 is defined as Clear

On Wed, Oct 5, 2022, 9:45 AM accounts <burnsds.accounts(a)protonmail.com>
wrote:

> Wow this is really helpful.  Do you know if the request values are vendor
> specific?  It would be nice to know what the different values mean.
>
> Thanks,
> Dan
>
> ------- Original Message -------
> On Friday, September 30th, 2022 at 4:07 PM, Steven Clark <
> davolfman(a)gmail.com> wrote:
>
> Also there's the Physical Presence Interface if your device supports it.
> You echo a number representing the type of reset you want to the sysfs path
> at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at
> /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's
> platform authority to issue a clear, usually after prompting you to press
> some key to indicate you're at the console and agree.
>
> For example:
> $echo 5 > /sys/class/tpm/tpm0/ppi/request
> $reboot
>
> On Fri, Sep 30, 2022, 12:50 PM Roberts, William C <
> william.c.roberts(a)intel.com> wrote:
>
>> On Fri, 2022-09-30 at 17:46 +0000, burnsds.accounts(a)protonmail.com
>> wrote:
>> > Is there any way to get out of this state without the lockout
>> > password?
>>
>> Platform auth, which you won't have as its typically randomly set by
>> the OS on boot or you can use the bios settings to clear an Intel or
>> AMD based TPM. For discrete TPMs you need to consult their manuals.
>> Typically, its playing with some jumpers.
>>
>> > _______________________________________________
>> > tpm2 mailing list -- tpm2(a)lists.01.org
>> > To unsubscribe send an email to tpm2-leave(a)lists.01.org
>> > %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
>> _______________________________________________
>> tpm2 mailing list -- tpm2(a)lists.01.org
>> To unsubscribe send an email to tpm2-leave(a)lists.01.org
>> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
>>
>
>
attachment.htm (text/html, 3.6 KB)
<div dir="auto">The codes are defined in Table 2 of the document &quot;TCG PC Client Platform Physical Presence Interface Specification&quot; which you can find on the Trusted Computing Group website.   5 is defined as Clear</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Oct 5, 2022, 9:45 AM accounts &lt;<a href="mailto:[email protected]">[email protected]</a>&gt; wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)">Wow this is really helpful.  Do you know if the request values are vendor specific?  It would be nice to know what the different values mean.</div><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)"><br>Thanks,<br>Dan</div><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)"><br></div><div>
        ------- Original Message -------<br>
        On Friday, September 30th, 2022 at 4:07 PM, Steven Clark &lt;<a href="mailto:[email protected]" target="_blank" rel="noreferrer">[email protected]</a>&gt; wrote:<br><br>
        <blockquote type="cite">
            <div dir="auto">Also there&#39;s the Physical Presence Interface if your device supports it.  You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot.  The BIOS then uses it&#39;s platform authority to issue a clear, usually after prompting you to press some key to indicate you&#39;re at the console and agree.<div dir="auto"><br></div><div dir="auto">For example:</div><div dir="auto">$echo 5 &gt; /sys/class/tpm/tpm0/ppi/request</div><div dir="auto">$reboot</div></div><br><div class="gmail_quote"><div class="gmail_attr" dir="ltr">On Fri, Sep 30, 2022, 12:50 PM Roberts, William C &lt;<a href="mailto:[email protected]" rel="noreferrer nofollow noopener noreferrer" target="_blank">[email protected]</a>&gt; wrote:<br></div><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex" class="gmail_quote">On Fri, 2022-09-30 at 17:46 +0000, <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br>
wrote:<br>
&gt; Is there any way to get out of this state without the lockout<br>
&gt; password?<br>
<br>
Platform auth, which you won&#39;t have as its typically randomly set by<br>
the OS on boot or you can use the bios settings to clear an Intel or<br>
AMD based TPM. For discrete TPMs you need to consult their manuals.<br>
Typically, its playing with some jumpers. <br>
<br>
&gt; _______________________________________________<br>
&gt; tpm2 mailing list -- <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br>
&gt; To unsubscribe send an email to <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br>
&gt; %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
_______________________________________________<br>
tpm2 mailing list -- <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br>
To unsubscribe send an email to <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br>
</blockquote></div>

        </blockquote><br>
    </div></blockquote></div>