Conversation

Jarkko Sakkinen

Edited yesterday
Now it hit me what I was doing wrong in TPM2 asymmetric keys.

Introducing new key types was a wrong strategy. Instead, pre-existing ECC and RSA key types should be layered i.e., you turn "TPM2 magic switch" on and kernel generates import blob etc. dance behind the curtains.

This has numerous benefits. E.g., there can be then also "TEE magic switch" depending on platform and generally speaking this is the best for users as they don't need to overturn their configuration.

#linux #kernel #tpm
0
0
1