[tpm2] Re: Clearing TPM
Steven Clark <davolfman at gmail.com> Wed, 05 Oct 2022 11:47:10 -0700
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <CAOCvsS=XKSPqPtO7RtvP-Zn67nbV84OtoALOLcbCmzETYidUFw@mail.gmail.com> |
The codes are defined in Table 2 of the document "TCG PC Client Platform Physical Presence Interface Specification" which you can find on the Trusted Computing Group website. 5 is defined as Clear On Wed, Oct 5, 2022, 9:45 AM accounts <burnsds.accounts(a)protonmail.com> wrote: > Wow this is really helpful. Do you know if the request values are vendor > specific? It would be nice to know what the different values mean. > > Thanks, > Dan > > ------- Original Message ------- > On Friday, September 30th, 2022 at 4:07 PM, Steven Clark < > davolfman(a)gmail.com> wrote: > > Also there's the Physical Presence Interface if your device supports it. > You echo a number representing the type of reset you want to the sysfs path > at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at > /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's > platform authority to issue a clear, usually after prompting you to press > some key to indicate you're at the console and agree. > > For example: > $echo 5 > /sys/class/tpm/tpm0/ppi/request > $reboot > > On Fri, Sep 30, 2022, 12:50 PM Roberts, William C < > william.c.roberts(a)intel.com> wrote: > >> On Fri, 2022-09-30 at 17:46 +0000, burnsds.accounts(a)protonmail.com >> wrote: >> > Is there any way to get out of this state without the lockout >> > password? >> >> Platform auth, which you won't have as its typically randomly set by >> the OS on boot or you can use the bios settings to clear an Intel or >> AMD based TPM. For discrete TPMs you need to consult their manuals. >> Typically, its playing with some jumpers. >> >> > _______________________________________________ >> > tpm2 mailing list -- tpm2(a)lists.01.org >> > To unsubscribe send an email to tpm2-leave(a)lists.01.org >> > %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s >> _______________________________________________ >> tpm2 mailing list -- tpm2(a)lists.01.org >> To unsubscribe send an email to tpm2-leave(a)lists.01.org >> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s >> > >
attachment.htm
(text/html, 3.6 KB)
<div dir="auto">The codes are defined in Table 2 of the document "TCG PC Client Platform Physical Presence Interface Specification" which you can find on the Trusted Computing Group website. 5 is defined as Clear</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Oct 5, 2022, 9:45 AM accounts <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)">Wow this is really helpful. Do you know if the request values are vendor specific? It would be nice to know what the different values mean.</div><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)"><br>Thanks,<br>Dan</div><div style="font-family:Arial;font-size:14px;color:rgb(0,0,0)"><br></div><div> ------- Original Message -------<br> On Friday, September 30th, 2022 at 4:07 PM, Steven Clark <<a href="mailto:[email protected]" target="_blank" rel="noreferrer">[email protected]</a>> wrote:<br><br> <blockquote type="cite"> <div dir="auto">Also there's the Physical Presence Interface if your device supports it. You echo a number representing the type of reset you want to the sysfs path at /sys/class/tpm/tpm0/ppi/request, read out the success or failure at /sys/class/tpm/tpm0/ppi/response and reboot. The BIOS then uses it's platform authority to issue a clear, usually after prompting you to press some key to indicate you're at the console and agree.<div dir="auto"><br></div><div dir="auto">For example:</div><div dir="auto">$echo 5 > /sys/class/tpm/tpm0/ppi/request</div><div dir="auto">$reboot</div></div><br><div class="gmail_quote"><div class="gmail_attr" dir="ltr">On Fri, Sep 30, 2022, 12:50 PM Roberts, William C <<a href="mailto:[email protected]" rel="noreferrer nofollow noopener noreferrer" target="_blank">[email protected]</a>> wrote:<br></div><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex" class="gmail_quote">On Fri, 2022-09-30 at 17:46 +0000, <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br> wrote:<br> > Is there any way to get out of this state without the lockout<br> > password?<br> <br> Platform auth, which you won't have as its typically randomly set by<br> the OS on boot or you can use the bios settings to clear an Intel or<br> AMD based TPM. For discrete TPMs you need to consult their manuals.<br> Typically, its playing with some jumpers. <br> <br> > _______________________________________________<br> > tpm2 mailing list -- <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br> > To unsubscribe send an email to <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br> > %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br> _______________________________________________<br> tpm2 mailing list -- <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br> To unsubscribe send an email to <a rel="noreferrer nofollow noopener noreferrer" href="mailto:[email protected]" target="_blank">[email protected]</a><br> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s<br> </blockquote></div> </blockquote><br> </div></blockquote></div>