Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-28 Thread Stefan Berger
ups.io; stef...@linux.ibm.com; Yao, Jiewen ; Jeremiah Cox ; Michael Kubacki *Cc:* Marc-André Lureau *Subject:* Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth Adding @Jeremiah <mailto:jere...@microsoft.com>… Jeremiah, weren’t you or @Michael <mail

Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-28 Thread Michael Kubacki
nux.ibm@groups.io> *Sent: *Monday, July 26, 2021 7:48 AM *To: *Yao, Jiewen <mailto:jiewen@intel.com>; devel@edk2.groups.io <mailto:devel@edk2.groups.io> *Cc: *Marc-André Lureau <mailto:marcandre.lur...@redhat.com> *Subject: *[EXTERNAL] [edk2-devel] Missing TPM 2 relate

Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-27 Thread Stefan Berger
lto:stefanb=linux.ibm@groups.io> *Sent: *Monday, July 26, 2021 7:48 AM *To: *Yao, Jiewen <mailto:jiewen@intel.com>; devel@edk2.groups.io <mailto:devel@edk2.groups.io> *Cc: *Marc-André Lureau <mailto:marcandre.lur...@redhat.com> *Subject: *[EXTERNAL] [edk2-devel] Missing TPM

Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-27 Thread Yao, Jiewen
6, 2021 7:48 AM To: Yao, Jiewen<mailto:jiewen@intel.com>; devel@edk2.groups.io<mailto:devel@edk2.groups.io> Cc: Marc-André Lureau<mailto:marcandre.lur...@redhat.com> Subject: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth Hello! The TPM 2

Re: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-27 Thread Bret Barkelew via groups.io
AM To: Yao, Jiewen<mailto:jiewen@intel.com>; devel@edk2.groups.io<mailto:devel@edk2.groups.io> Cc: Marc-André Lureau<mailto:marcandre.lur...@redhat.com> Subject: [EXTERNAL] [edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth Hello! The TPM 2 code in

[edk2-devel] Missing TPM 2 related call to Tpm2HierarchyChangeAuth

2021-07-26 Thread Stefan Berger
Hello!   The TPM 2 code in EDK2 is missing an important call to Tpm2HierarchyChangeAuth for the platform hierarchy. We have to set the password of that hierarchy and discard the password. See also specs section 11: https://trustedcomputinggroup.org/wp-content/uploads/TCG_PCClient_PFP_r1p05_v2