On 5/9/2016 7:35 AM, Jan Schermer wrote:
> Hello, I want to seal data (a passphrase) to PCR >15.
>
> # tpm_nvdefine -i 1 -s 6 p -r 18 -w 18 --permissions="AUTHWRITE" -z
> Cannot seal NVRAM area to PCR > 15
>
> Why is this not possible? I want to seal to Intel TXT generated PCRs
> and this doesn't sound right... should I recompile with this check
> commented out and try?

Are there any code comments that explain why PCR > 15 is being rejected?

The only rationale I can think of is that this is left over from TPM 
1.1b, which I recall only had 16 PCRs.




------------------------------------------------------------------------------
Mobile security can be enabling, not merely restricting. Employees who
bring their own devices (BYOD) to work are irked by the imposition of MDM
restrictions. Mobile Device Manager Plus allows you to control only the
apps on BYO-devices by containerizing them, leaving personal data untouched!
https://ad.doubleclick.net/ddm/clk/304595813;131938128;j
_______________________________________________
TrouSerS-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/trousers-users

Reply via email to