WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

[Xen-devel] vtpm_managerd and default passwords

To: xen-devel@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-devel] vtpm_managerd and default passwords
From: Luke <secureboot@xxxxxxxxx>
Date: Thu, 26 Jul 2007 10:56:30 -0400
Delivery-date: Thu, 26 Jul 2007 07:54:12 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Thunderbird 1.5.0.12 (X11/20070604)
Looking through the code in tools/vtpm_manager/manager/vtpm_manager.c, I
see that when you start the vtpm_manager for the first time, that it
takes ownership of the TPM and sets the password to be 20 unprintable
ascii characters (0xff 20 times).

This seems to work fine, but later, I want to create a key with the TPM.
 I've made a file using python, using:

a = ""
for i in range(20):
        a = a + "\xff"
open("ascii_file","w").write(a)

when I use that as the password, I still get TPM_AUTHFAIL.
This is using the createkey utility found at:
http://domino.research.ibm.com/comm/research_projects.nsf/pages/gsal.TCG.html/$FILE/tpm-3.2.0.tar.gz

It's pretty straightforward, so I'm wondering if I'm not understanding
how the SRK password gets set in actuality.

Any ideas on what I might be doing wrong/how to fix this?

Specifically, should vtpm_managerd take an SRK password as a parameter?
 This seems much more sane.  Does this exist already, and I've just
missed it?

Apologies if this is more xen-user than xen-devel.

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel

<Prev in Thread] Current Thread [Next in Thread>