-
Bug
-
Resolution: Unresolved
-
Undefined
-
rhel-10.0
-
No
-
Moderate
-
rhel-security-special-projects
-
12
-
1
-
False
-
False
-
-
Yes
-
None
-
None
-
None
-
Unspecified Release Note Type - Unknown
-
Unspecified
-
Unspecified
-
Unspecified
-
None
What were you trying to do that didn't work?
Setting one of `ecc521`, `ecc384`, `ecc256` or `ecc` in `tpm_encryption_alg` in the agent configuration makes the attestation to fail
What is the impact of this issue to you?
The agent cannot generate TPM quote evidence to report to the verifier, making the whole Keylime solution to not work when TPM ECC keys are usedÂ
Please provide the package NVR for which the bug is seen:
keylime-7.12.1-11.el10
How reproducible is this bug?:
Always
Steps to reproduce
- Set any `ecc{521, 384, 256, }` to `tpm_encryption_alg` in the agent configuration
- Start the verifier, registrar, agent
- Enroll the agent to be monitored by the verifier using the tenant
Expected results
The agent is successfully enrolled and the verifier successfully verify the provided attestation evidences (TPM quotes)
Actual results
The attestation fails
- clones
-
RHEL-117441 keylime agent fails to create TPM quote with ECC keys
-
- In Progress
-
- is cloned by
-
RHEL-118150 keylime attestation fails when agent provide TPM quote with ECC keys [rhel-9]
-
- Planning
-