-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-9.5
-
clevis-21-206.el9
-
Yes
-
Moderate
-
Patch
-
1
-
rhel-sst-security-special-projects
-
ssg_security
-
12
-
14
-
None
-
False
-
-
No
-
Red Hat Enterprise Linux
-
SECENGSP Cycle 10
-
Unspecified Release Note Type - Unknown
-
None
The default PCR bank is sha1, which is not always supported (it is legacy and optional for implementation). Make this more future-proof and use the first bank with non-empty set of PCRs, which is returned from TPM by tpm2_getcap pcrs.
The swtpm by default does not create sha1 bank, so this fixes usage with swtpm
- is cloned by
-
RHEL-65469 [RHEL10] tpm2: use first PCR algorithm bank supported by TPM as default
-
- Release Pending
-
- links to
-
RHBA-2024:139484 clevis bug fix and enhancement update