Linux and UNIX Man Pages

Linux & Unix Commands - Search Man Pages

tspi_tpm_cmksetrestrictions(3) [debian man page]

Tspi_TPM_CMKSetRestrictions(3)				     Library Functions Manual				    Tspi_TPM_CMKSetRestrictions(3)

						     TCG Software Stack Developer's Reference

NAME
Tspi_TPM_CMKSetRestrictions - set restrictions on use of delegated Certified Migratable Keys SYNOPSIS
#include <tss/tspi.h> TSS_RESULT Tspi_TPM_CMKSetRestrictions(TSS_HTPM hTPM, TSS_CMK_DELEGATE CmkDelegate); DESCRIPTION
Tspi_TPM_CMKSetRestrictions is used to set restrictions on the delegated use of Certified Migratable Keys (CMKs). Use of this command can- not itself be delegated. PARAMETERS
hTPM The hTPM parameter is used to specify the handle of the TPM object. CmkDelegate The CmkDelegate parameter is a bitmask describing the kinds of CMKs that can be used in a delegated auth session. Each bit represents a type of key. If the bit of a key type is set, then the CMK can be used in a delegated authorization session, otherwise use of that key will result in a TPM_E_INVALID_KEYUSAGE return code from the TPM. The possible values of CmkDelegate are any combination of the following flags logically OR'd together: TSS_CMK_DELEGATE_SIGNING Allow use of signing keys. TSS_CMK_DELEGATE_STORAGE Allow use of storage keys. TSS_CMK_DELEGATE_BIND Allow use of binding keys. TSS_CMK_DELEGATE_LEGACY Allow use of legacy keys. TSS_CMK_DELEGATE_MIGRATE Allow use of migratable keys. RETURN CODES
Tspi_TPM_CMKSetRestrictions returns TSS_SUCCESS on success, otherwise one of the following values is returned: TSS_E_INVALID_HANDLE hTPM is not a valid handle. TSS_E_INTERNAL_ERROR An internal SW error has been detected. CONFORMING TO
Tspi_TPM_CMKSetRestrictions conforms to the Trusted Computing Group Software Specification version 1.2 Errata A SEE ALSO
Tspi_TPM_CMKApproveMA(3), Tspi_TPM_CMKCreateTicket(3), Tspi_Key_CMKCreateBlob(3) TSS 1.2 2007-12-13 Tspi_TPM_CMKSetRestrictions(3)

Check Out this Related Man Page

Tspi_TPM_GetPubEndorsementKey(3)			     Library Functions Manual				  Tspi_TPM_GetPubEndorsementKey(3)

						     TCG Software Stack Developer's Reference

NAME
Tspi_TPM_GetPubEndorsementKey - create a TSS key object from the TPM's public endorsement key SYNOPSIS
#include <tss/platform.h> #include <tss/tcpa_defines.h> #include <tss/tcpa_typedef.h> #include <tss/tcpa_struct.h> #include <tss/tss_typedef.h> #include <tss/tss_structs.h> #include <tss/tspi.h> TSS_RESULT Tspi_TPM_GetPubEndorsementKey(TSS_HTPM hTPM, TSS_BOOL fOwnerAuthorized, TSS_VALIDATION* pValidationData, TSS_HKEY* phEndorsementPubKey); DESCRIPTION
Tspi_TPM_GetPubEndorsementKey This function retrieves the public endorsement key (PubEK) from the TPM and creates a TSS key object for it, whose handle is returned in phEndorsementPubKey. Due to the fact that different TPM chips validate the PubEK in different ways, application verification of the PubEK (using a non-NULL pValidationData is broken. Tspi_TPM_GetPubEndorsementKey should be called with a NULL pValida- tionData parameter to allow the TSS to verify the PubEK itself. PARAMETERS
hTPM The hTPM parameter is used to specify the handle of the TPM object. fOwnerAuthorized If TRUE, the TPM owner secret must be provided to get the public endorsement key. If FALSE, no TPM owner secret must be provided to get the public endorsement key. pValidationData If non-NULL, the application should set the pValidationData->rgbExternalData parameter to 20 bytes of random data before calling Tspi_TPM_GetPubEndorsementKey. On successful completion of the command, the structure will provide buffers containing the validation data and the buffer the validation data was computed from. phEndorsementPubKey Receives a handle to a key object representing the TPM's public endorsement key. RETURN CODES
Tspi_TPM_GetPubEndorsementKey returns TSS_SUCCESS on success, otherwise one of the following values is returned: TSS_E_INVALID_HANDLE hTPM is not a valid handle. TSS_E_INTERNAL_ERROR An internal SW error has been detected. TSS_E_BAD_PARAMETER One or more parameters is bad. TPM_E_DISABLED_CMD Reading of PubEK from TPM has been disabled. CONFORMING TO
Tspi_TPM_GetPubEndorsementKey conforms to the Trusted Computing Group Software Specification version 1.1 Golden SEE ALSO
Tspi_Key_GetPubKey(3). TSS 1.1 2004-05-25 Tspi_TPM_GetPubEndorsementKey(3)
Man Page