|
From: Nauman <re...@gm...> - 2008-03-17 05:23:16
|
Hi,
I'm having a little trouble with signing TPM PCRs with an AIK (created with
jTPM Tools). Here's what I've done.
1. Created an AIK with jTPMTools.
2. Used this code to get a TPM Quote:
// 20 byte nonce
byte nonce[] = { 0x1, 0x2, 0x3, 0x4, 0x5, 0x1, 0x2, 0x3, 0x4, 0x5, 0x1, 0x2,
0x3, 0x4, 0x5, 0x1, 0x2, 0x3, 0x4, 0x5 };
// create a TCBlobData using the provided nonce
TcBlobData nonceData = TcBlobData.newByteArray(nonce);
TcTssValidation nonceVal = new TcTssValidation();
nonceVal.setExternalData(nonceData);
// the tpmQuote to receive data from tpm's quote
TcTssValidation tpmQuote = new TcTssValidation();
TcIContext context = CommonSettings.getTssFactory()
.newContextObject();
context.connect(null); // connect to localhost
TcITpm tpm = context.getTpmObject();
// get the number of PCRs from TPM
TcBlobData subCap = TcBlobData
.newUINT32((int) TcTssConstants.TSS_TPMCAP_PROP_PCR);
long numPCRs = tpm.getCapabilityUINT32(
TcTssConstants.TSS_TPMCAP_PROPERTY, subCap);
for (int i = 0; i < numPCRs; i++) {
// create a pcr composite object
TcIPcrComposite pcrComp = context.createPcrCompositeObject
(0);
pcrComp.selectPcrIndex(i);
// set pcr value to read
pcrComp.setPcrValue(i, tpm.pcrRead(i));
// first loading the SRK
TcBlobData srkSecret = TcBlobData
.newByteArray(TcTssConstants.TSS_WELL_KNOWN_SECRET);
// I set an owner secret when taking ownership but didn't provide an SRK
secret... so it should be on Well_known_secret, right?
long srkSecretMode = TcTssConstants.TSS_SECRET_MODE_SHA1;
// create the UUID of the AIK
TcTssUuid uuid = new
TcTssUuid().initString("00000001-0002-0003-0405-6576352a7d41");
*// this is the UUID I got from jtt.sh list_keys ... is this a problem? If
it is, how do I get a UUID of an AIK? *
// set the key password
TcBlobData keySecret = TcBlobData.newString("someSecret",
false, "UTF-16LE");
// i've tried appending the null terminator to the string too...
// load the SRK
TcIRsaKey srk = context.loadKeyByUuidFromSystem(
TcUuidFactory.getInstance().getUuidSRK());
TcIPolicy srkPolicy = context.createPolicyObject(
TcTssConstants.TSS_POLICY_USAGE);
srkPolicy.setSecret(srkSecretMode, srkSecret);
srkPolicy.assignToObject(srk);
// the AIK
TcIRsaKey identityKey = context.getKeyByUuid(
TcTssConstants.TSS_PS_TYPE_SYSTEM, uuid);
TcIPolicy keyUsgPolicy = context.createPolicyObject(
TcTssConstants.TSS_POLICY_USAGE);
keyUsgPolicy.setSecret(TcTssConstants.TSS_SECRET_MODE_PLAIN,
keySecret);
keyUsgPolicy.assignToObject(identityKey);
identityKey.loadKey(srk);
// now get the quote
tpmQuote = tpm.quote(identityKey, pcrComp, nonceVal);
// output signed value
System.out.println(pcrComp.getPcrValue
(i).toHexStringNoWrap());
...
And here's the output I get:
*iaik.tc.tss.api.exceptions.tcs.TcTpmException: *
*TSS Error:*
*error layer: 0x00 (TPM)*
*error code (without layer): 0x01*
*error code (full): 0x01*
*error message: Authentication failed*
* at iaik.tc.tss.impl.java.tcs.pbg.TcTpmCmdCommon.handleRetCode(Unknown
Source)*
* at iaik.tc.tss.impl.java.tcs.pbg.TcTpmCmdIntegrity.TpmQuote(Unknown
Source)*
* at iaik.tc.tss.impl.java.tcs.tcsi.TcTcsi.TcsipQuote(Unknown Source)*
* at
iaik.tc.tss.impl.java.tsp.tcsbinding.local.TcTcsBindingLocal.TcsipQuote(Unknown
Source)*
* at iaik.tc.tss.impl.java.tsp.internal.TcTspInternal.TspQuote_Internal(Unknown
Source)*
* at iaik.tc.tss.impl.java.tsp.TcTpm.quote(Unknown Source)*
* at serg.mba.wsa.client.attestor.PCRAttestor.process(PCRAttestor.java
:142)*
* at serg.mba.wsa.client.MainClient.main(MainClient.java:44)*
*15:13:13:192 [ERROR] PCRAttestor::process (155): *
*TSS Error:*
*error layer: 0x00 (TPM)*
*error code (without layer): 0x01*
*error code (full): 0x01*
*error message: Authentication failed*
Can anyone help me about this issue? What am I doing wrong here?
--
Nauman
Security Engineering Research Group,
Institute of Management Sciences,
Peshawar, Pakistan.
Blog: http://recluze.wordpress.com
Group: http://serg.imsciences.edu.pk
Art gallery: http://recluse.gfxartist.com
Cell: 0321 90 66 275
|