-
Bug
-
Resolution: Unresolved
-
Undefined
-
rhel-10.0
-
No
-
Moderate
-
rhel-security-special-projects
-
12
-
1
-
False
-
False
-
-
Yes
-
None
-
None
-
None
-
Unspecified Release Note Type - Unknown
-
Unspecified
-
Unspecified
-
Unspecified
-
None
What were you trying to do that didn't work?
Setting one of `ecc521`, `ecc384`, `ecc256` or `ecc` in `tpm_encryption_alg` makes the agent to fail generating signed TPM quotesÂ
What is the impact of this issue to you?
The agent cannot generate TPM quote evidence to report to the verifier, making the whole Keylime solution to not work when TPM ECC keys are usedÂ
Please provide the package NVR for which the bug is seen:
keylime-agent-rust-0.2.7-3.el10
How reproducible is this bug?:
Always
Steps to reproduce
- Set any `ecc{521, 384, 256, }` to `tpm_encryption_alg`
- Start the verifier, registrar, agent
- Enroll the agent to be monitored by the verifier using the tenant
Expected results
The agent is successfully enrolled and the verifier successfully verify the provided attestation evidences (TPM quotes)
Actual results
The enrollment fails
- is cloned by
-
RHEL-118148 keylime agent fails to create TPM quote with ECC keys [rhel-9]
-
- Planning
-
-
RHEL-117442 keylime attestation fails when agent provide TPM quote with ECC keys
-
- In Progress
-