Menu

#146 Support TPM_KEY.keyFlags.pcrIgnoredOnRead

Bug
closed-accepted
5
2011-12-06
2011-08-31
Kent Yoder
No

This flag controls whether the TPM should check use of the public key portion of the key in APIs like TPM_CertifyKey TPM_CertifyKey2 and TPM_GetPubKey. By default the flag should be 1, since users will not be expecting for instance that their PCR composite is checked on a key being certified.

Right now trousers leaves this bit as 0 in the keyFlags and therefore these checks are enabled.

Discussion

  • Rajiv Andrade

    Rajiv Andrade - 2011-12-06
    • status: open --> closed-accepted
     

Log in to post a comment.