Using TPM2_LoadExternal() for loading an HMAC key into the TPM?
Lennart Poettering <[email protected]> Tue, 16 Apr 2024 15:05:51 +0200
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <Zh53rw5o97SVXZWT@gardel-login> |
Hi!
I was wondering, if anyone has an idea how precisely to set up a pair
of TPM2B_PUBLIC and TPM2_SENSITIVE structures for loading an
HMAC-SHA256 key into the TPM via TPM_LoadExternal()?
I am currently setting things up more or less like this:
TPM2B_PUBLIC auth_hmac_public = {
.size = sizeof(TPMT_PUBLIC),
.publicArea = {
.type = TPM2_ALG_KEYEDHASH,
.nameAlg = TPM2_ALG_SHA256,
.objectAttributes = TPMA_OBJECT_DECRYPT | TPMA_OBJECT_SIGN_ENCRYPT /* | TPMA_OBJECT_USERWITHAUTH */,
.parameters.keyedHashDetail.scheme.scheme = TPM2_ALG_SHA256,
.unique.keyedHash.size = buffer.size,
},
};
TPM2B_SENSITIVE auth_hmac_private = {
.size = sizeof(TPMT_SENSITIVE),
.sensitiveArea = {
.sensitiveType = TPM2_ALG_KEYEDHASH,
.sensitive.sym.size = buffer.size,
},
};
memcpy(auth_hmac_private.sensitiveArea.sensitive.sym.buffer, buffer.buffer, buffer.size);
And then use TPM2_LoadExternal() with this, for the NULL hierarchy.
tpm2-tss responds with these errors:
ERROR:esys:src/tss2-esys/api/Esys_LoadExternal.c:184:Esys_LoadExternal_Async() SAPI Prepare returned error. ErrorCode (0x0009000b)
ERROR:esys:src/tss2-esys/api/Esys_LoadExternal.c:85:Esys_LoadExternal() Error in async function ErrorCode (0x0009000b)
But, uh, what am I supposed to make of this?
I figure it's not even the TPM that refuses this, but it's tpm2-tss
already?
Anyone has an idea?
(Background: I am trying to protect an nvindex that I want to use with
TPM2_AuthorizeNV, with an TPM2_PolicySigned access policy. I want to
use an HMAC key for the signature scheme. If you want to know even
more, see → https://github.com/systemd/systemd/pull/31790. The above
is more or less a copy of the topmost commit of that)
Any help appreciated!
Lennart