Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TPM 2.0 with Cr50 #626

Open
ChocolateLoverRaj opened this issue Apr 28, 2024 · 6 comments
Open

TPM 2.0 with Cr50 #626

ChocolateLoverRaj opened this issue Apr 28, 2024 · 6 comments

Comments

@ChocolateLoverRaj
Copy link

It would be really convenient having automatic LUKS unlocking with TPM on Chromebooks, but it doesn't work rn. Are there plans for it to be implemented?

@MrChromebox
Copy link
Owner

there's nothing I can do about the fact that the CR50 is not a full TPM 2.0 implementation. I'm not sure if it's sufficient for what you're asking

@tlaurion
Copy link

tlaurion commented Nov 16, 2024

@MrChromebox tpm2-software/tpm2-tools#3434

Blocker for linuxboot/heads#1658 (comment) (TPM released Disk Unlock Key: sealing of secret in nvram fails)

@MrChromebox
Copy link
Owner

@MrChromebox tpm2-software/tpm2-tools#3434

Blocker for linuxboot/heads#1658 (comment) (TPM released Disk Unlock Key: sealing of secret in nvram fails)

@tlaurion CR50 is not a fully TPM 2.0 compliant implementation, as per my comment above. I don't think there's anything missing from the firmware init, other TPM 2.0 chips are fine

@tlaurion
Copy link

tlaurion commented Nov 20, 2024

@MrChromebox tpm2-software/tpm2-tools#3434

Blocker for linuxboot/heads#1658 (comment) (TPM released Disk Unlock Key: sealing of secret in nvram fails)

@tlaurion CR50 is not a fully TPM 2.0 compliant implementation, as per my comment above. I don't think there's anything missing from the firmware init, other TPM 2.0 chips are fine

tpm2-software/tpm2-tools#3434 (comment)

Two secrets are sealed with same policy, one succeeds (TPM totp with tpm2), where sealing TPM disk unlock key in seperate nvram region fails.

Two logs provided at linuxboot/heads#1658 (comment)

@MrChromebox
Copy link
Owner

@tlaurion again I'm not sure what I can do from the firmware init side, or even what you're asking for.

@tlaurion
Copy link

@tlaurion again I'm not sure what I can do from the firmware init side, or even what you're asking for.

tpm2-software/tpm2-tools#3434 (comment)

Feature missing from tpm2 implementation, so nothing you can do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants