|
From: Ronald T. <ron...@ia...> - 2009-09-16 08:07:45
|
Hi, First of all, there should not be a difference - I do not understand why it is there and will look into this. Second: Your key hierarchy is not correct. The TPM owner authorisation is only needed for a few restricted operations, not for everyday application key creation. A pop-up will always appear if a policy to some object is missing. The root for key creation should be the Storage Root Key, which needs to be designated as parent at key creation. Here you need to have the SRK object with the proper usage policy (by convention using TSS_WELL_KNOWN_SECRET) assigned. A good reading on how to handle TPM keys is "A Practical Guide to Trusted Computing" by David Challener; Kent Yoder; Ryan Catherman; David Safford; Leendert van Doorn hth, Ronald Arshad Noor wrote: > Hi, > > Is there a reason why the creation of a Signing key-pair always > prompts for the TPM Owner's password through a pop-up even though > the password is set in a BlobData structure and the Usage policy > for the TPM (set with the TPM Owner's password) is assigned to the > TPM? The signing keys are set to be non-migratable. > > This behavior is markedly different from creating migratable Binding > keys where the same secret and policy settings do not prompt for the > TPM Owner's password. > > Any pointers to an explanation, and a suggestion for how to avoid > the pop-up for the signing-key creation, would be appreciated. > Thanks. > > Arshad Noor > StrongAuth, Inc. -- Dipl.-Ing. Ronald Tögl phone +43 316/873-5502 Trusted Computing Labs fax +43 316/873-5520 IAIK ron...@ia... Graz University of Technology http://www.iaik.tugraz.at |