Re: TPM2_Sign vs TPM2_RSA_Decrypt
James Prestwood <[email protected]> Thu, 16 May 2024 06:59:01 -0700
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <[email protected]> |
On 5/16/24 6:55 AM, Jarkko Sakkinen wrote: > On Thu May 16, 2024 at 4:44 PM EEST, James Prestwood wrote: >> To be honest I started with encrypt/decrypt and included the signing >> operation because it was basically "free" by using tpm2_rsa_decrypt(). I >> was not aware of this distinction/difference between that and doing >> signing on the TPM itself. I don't think I ever looked into the signing >> command on the TPM itself. > My personal take: I'd start RSA with the working code and just > clean up the parts for the first round. It is tested code and > does the job, right? :-) It was tested then yes, obviously need to verify that after 4 years :) > > Then we will weight the odds and cons in the review. That said, > if you want to use TPM_Sign and TPM2_EncryptDecrypt(2) that is > fine too, but not demand. > > As for ECDSA, it can be part of the patch set, or we can start > just with the RSA part. > Andreas, is it OK if the patch set is CC'd to you so you can > give your feedback/remarks on it? > > BR, Jarkko