Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-113400

Cannot export EK certificate using tpm2_getekcertificate

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-9.8
    • rhel-9.6
    • tpm2-tools
    • None
    • No
    • None
    • rhel-kernel-security
    • 0
    • Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • None
    • None
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • s390x
    • None

      What were you trying to do that didn't work?

      1. tpm2_getekcertificate -o /tmp/tmp.0S92efWD9f/ek.der
        ERROR: Must specify the EK public key path
        Usage: tpm2_getekcertificate [<options>] <arguments>
        Where <options> are:
            [ -o | --ek-certificate=<value>] [ -X | --allow-unverified] [ -u | --ek-public=<value>] [ -x | --offline]
            [ --raw]

        What is the impact of this issue to you?

      cannot export EK certificate this way

      Please provide the package NVR for which the bug is seen:

      tpm2-tools-5.2-6.el9.s390x

       

      The issue is on s390x only

      the package is probably missing this patch

      https://github.com/tpm2-software/tpm2-tools/commit/f2adc763577fc80f502bef748ac6da5f8e066aae

       

      How reproducible is this bug?:

      always

      Steps to reproduce

      1. see above
      2.  
      3.  

      Expected results

      EK certificate is exported

              shoracek@redhat.com Štěpán Horáček
              ksrot@redhat.com Karel Srot
              Štěpán Horáček Štěpán Horáček
              Security Kernel Security Kernel
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: