Skip to content

How to use swtpm_cert for QEMU to mock another PCs TPM EK Cert? #834

Answered by stefanberger
CE1CECL asked this question in Q&A
Discussion options

You must be logged in to vote

Since you don't have access to the CA of the TPM manufacturer you will not be able to create an EK cert with the signature of the manufacturer's (well known) CA. Also, you cannot just reuse the EK cert of the hardware TPM because you would be missing the corresponding EK private key.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@CE1CECL
Comment options

@stefanberger
Comment options

Answer selected by CE1CECL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants