|
From: <dna...@de...> - 2012-06-20 00:40:30
|
After successfully running the activateIdentity command, how do I pull
the activated AIK from the TPM for signing the quote? I could not find
any sample code that demonstrates this.
At the moment, I am registering the AIK PubKey to the TPM using a UUID
during the collateIdentityRequest command. I then pull it at a later
point in time when I wish to sign the quote. I don't think the current
way I am doing this is the correct way. Any insight or direction would
be greatly appreciated.
TcITpm tpm = context_.getTpmObject();
TestDefines.tpmPolicy.assignToObject(tpm);
UUID uuid = UUID.fromString("2426c67e-9a0f-4588-bde5-fde2c23b0be9");
TcTssUuid keyUUID =
TcUuidFactory.getInstance().convertUuidJavaToTss(uuid);
TcIRsaKey aikKey =
context_.getKeyByUuid(TcTssConstants.TSS_PS_TYPE_SYSTEM, keyUUID);
setAIKKeyPolicies(aikKey);
aikKey.loadKey(srk_);
..... etc
Object[] tpmOutData = tpm.quote2(aikKey, false, pcrComp, null);
..... etc
Thanks,
David
|