nsacyber / HIRS

Trusted Computing based services supporting TPM provisioning and supply chain validation concepts. #nsacyber
Other
177 stars 57 forks source link

Sign CSR for LDevID generation #818

Open iadgovuser59 opened 1 month ago

iadgovuser59 commented 1 month ago

Currently, the CSR for LDevID creation is unsigned during the provisioning process. Per the TCG specification "TCG TPM 2.0 Keys for Device Identity and Attestation", we will need to:

Note: The above will only be applicable when an LDevID is present in the request.