wolfSSL / wolfTPM

wolfTPM is a highly portable TPM 2.0 library, designed for embedded use.
https://www.wolfssl.com
GNU General Public License v2.0
230 stars 55 forks source link

wolfTPM Support for sealing/unsealing based on a PCR that is signed externally #294

Closed dgarske closed 10 months ago

dgarske commented 10 months ago

Use an external key to sign a PCR digest. Allows a new signed policy to be sent with updates to continue allowing a sealed secret to be unsealed when PCR's change. This resolves the issue with PCR brittleness.

Removed experimental policy examples (will put back as draft PR).