tpm2_takeownership -o ownerpass -e endorsepass -l lockpass
ownership: 对TPM的操作权限的拥有者;
ownerpass是操作者对TPM设备进行操作的密码;
endorsepass是使用TPM进行背书/签名的密码,lockpass是对TPM进行锁定.
tpm2_takeownership -o ownerpassnew -e endorsepassnew -l lockpassnew -O ownerpass -E endorsepass -L lockpass
tpm2_takeownership -c [-L lockpass]
tpm2_nvdefine -x 0x1500001 -a 0x40000001 -s 32 -t 0x2000A -P ownerpass
tpm2_nvwrite -x 0x1500001 -a 0x40000001 -f nv.data -P ownerpass
tpm2_nvread -x 0x1500001 -a 0x40000001 -s 32 -o 0 -P ownerpass
tpm2_nvrelease -x 0x1500001 -a 0x40000001 -P ownerpass
tpm2_createprimary -A e -K objectpass -g 0x000b -G 0x0001 -C po.ctx
附:Supported Hash Algorithms
· 0x4 or sha1 for TPM_ALG_SHA1 (default)
· 0xB or sha256 for TPM_ALG_SHA256
· 0xC or sha384 for TPM_ALG_SHA384
· 0xD or sha512 for TPM_ALG_SHA512
· 0x12 or sm3_256 for TPM_ALG_SM3_256
附:Supported Public Object Algorithms
· 0x1 or rsa for TPM_ALG_RSA (default).
· 0x8 or keyedhash for TPM_ALG_KEYEDHASH.
· 0x23 or ecc for TPM_ALG_ECC.
· 0x25 or symcipher for TPM_ALG_SYMCIPHER.
tpm2_create -c po.ctx -P objectpass -K subobjectpass -g 0x000b -G 0x0001 -o key.pub -O key.priv
tpm2_load -c po.ctx -P objectpass -u key.pub -r key.priv -n key.name -C obj.ctx
tpm2_rsaencrypt -c obj.ctx -I data.in -o data.encrypted
tpm2_rsadecrypt -c obj.ctx -P subobjectpass -I data.encrypted -o data.out
tpm2_sign -c obj.ctx -P subobjectpass -g 0x000b -m msg.in -s sig.out
tpm2_verifysignature -c obj.ctx -g 0x000b -m msg.in -s sig.out -t tk.sig