-
Bug
-
Resolution: Won't Do
-
Normal
-
rhel-10.0
-
clevis-21-6.el10
-
No
-
Moderate
-
Patch
-
rhel-sst-security-special-projects
-
ssg_security
-
13
-
None
-
False
-
-
None
-
Red Hat Enterprise Linux
-
None
-
None
The default is PCR bank is sha1, which is not always supported (it is legacy and optional for implementation). Make this more future-proof and use the first bank with non-empty set of PCRs, which is returned from TPM by tpm2_getcap pcrs.
The swtpm by default does not create sha1 bank, so this fixes usage with swtpm
- clones
-
RHEL-65469 [RHEL10] tpm2: use first PCR algorithm bank supported by TPM as default
- Integration