Tree [9cb262] TROUSERS_0_1_8 /

HTTPS access

File Date Author Commit
 dist 2005-02-03 kyoder kyoder [e55b36] made script slightly more correct, still untest...
 doc 2005-01-14 kyoder kyoder [a0971a] add updated design doc
 man 2005-03-01 kyoder kyoder [c6d85a] added Tspi_TPM_PcrExtend
 src 2005-03-02 kyoder kyoder [72564b] in Tspi_SetAttribData, set the tcpaKey's privat...
 AUTHORS 2004-12-28 kyoder kyoder [981647] added blurb about IBM
 ChangeLog 2005-03-02 kyoder kyoder [028617] updated
 LICENSE 2004-12-10 kyoder kyoder [4c6a90] Initial revision 2004-12-10 kyoder kyoder [4c6a90] Initial revision
 NEWS 2004-12-10 kyoder kyoder [4c6a90] Initial revision
 NICETOHAVES 2004-12-10 kyoder kyoder [4c6a90] Initial revision
 README 2005-03-01 kyoder kyoder [80c44f] updated
 TODO 2005-02-01 kyoder kyoder [af82b1] updated
 aclocal.m4 2004-12-10 kyoder kyoder [4c6a90] Initial revision 2004-12-10 kyoder kyoder [4c6a90] Initial revision 2005-03-02 kyoder kyoder [9cb262] updated version number 2004-12-10 kyoder kyoder [4c6a90] Initial revision

Read Me

trousers README

  Trousers is an open-source TCG Software Stack (TSS), released under the Common Public
License. Trousers aims to be compliant with the current (1.1b) and upcoming (1.2)
TSS specifications available from the Trusted Computing Group website:


  Currently this software is BETA quality and will build, however it is not
fully functional.

  Packages needed to build:

  openssl-0.9.7 or newer
  openssl-devel-0.9.7 or newer
  pthreads library (glibc-devel)


  02/01/05: Right now there are 2 ways to get the TSS up and running:

  A Grab the source code for an older version of the TPM device driver from here:, configure, make, make
    install in the tpm-2.0 directory of that archive. Once that device driver is
    installed and loaded, change one line in src/include/tddl.h of the trousers
    source code:

    #undef TPM_IOCTL


    #define TPM_IOCTL

    Then build and install trousers. or,

  B Build and install a very recent -mm kernel with the latest TPM device driver
    either compiled in or loaded as a module. If you are doing this, trousers
    should just work after a vanilla build. Follow the build instructions below
    and don't worry about the device file changes in the RUNNING section below.

  To build trousers after you have the device driver installed:

  $ sh
  $ ./configure [--enable-debug] [--enable-prof] [--enable-efence] [--enable-gcov]
  $ make
  $ make install

  By default the build will place everything in /usr/local. To install in a
slightly more predictable place, use `./configure --prefix=/usr`.


  This TSS implementation has several components.

  A) The TCS Daemon - A user space daemon who should be (according to the TSS spec)
  the only portal to the TPM device driver. At boot time, the TCS Daemon should be
  started, it should open the TPM device driver and from that point on, all
  requests to the TPM should go through the TSS stack. The TCSD manages TPM
  resources and handles requests from TSP's both local and remote.

  B) The TSP shared library - The TSP (TCG Service Provider) is a shared library
  that enables applications to talk to TCSD's both locally and remotely. The TSP
  also manages resources used in commicating with the application and the TCSD
  and transparently contacts the TCSD whenever necessary

  C) Persistant storage files - TSS's have 2 different kinds of 'persistant'
  storage. 'User' persistant storage has the lifetime of that of the application
  using it (not very persistent, IMO) and therefore is destroyed when an application
  exits.  User PS is controlled by the TSP of the application.  'System' persistent
  storage is controlled by the TCS and stays valid across application lifetimes, TCSD
  restarts and system resets. Data registered in system PS stays valid until an
  application requests that it be removed. User PS files are by default stored as
  /var/tpm/user.{pid} and the system PS file by default is /var/tpm/ The
  system PS file is initially created when ownership of the TPM is first taken.

  D) A config file. By default located in $prefix/etc/tcsd.conf.


  Before running your app:

  If you're using the device driver from the IBM research site (section A of BUILDING),
you'll need to do the following to create a device node:

  1) Create the device file for your tpm
  # /bin/mknod /dev/tpm c 10 224
  2) Change the device settings:
  # chown tss:tss /dev/tpm
  # chmod 0600 /dev/tpm
  3) load the tpm device driver:
  # modprobe tpm

  If you're using the device driver in the -mm tree and have udev enabled, you
don't need to do any of the above stuff, just load the device driver with
  # modprobe tpm_atml
  # modprobe tpm_natl

  start the TCS Core Services daemon, by default /usr/local/sbin/tcsd.
  # startproc -u tss /usr/local/sbin/tcsd

  At this point your apps should be ready to run!

  'make install' will run ldconfig, but if /usr/local/lib is not in your
/etc/, this won't make a difference. You may need to manually
add it and run ldconfig as root to allow your apps to link at run time


 # sh
 # ./configure --prefix=/usr
 # cd ..
 # mv trousers trousers-${version}
 # tar zcvf /usr/src/packages/SOURCES/trousers-${version}.tar.gz trousers-${version}
 # rpmbuild -bb trousers-${version}/dist/trousers.spec