Skip to content

Add support for creating and persisting TPM Attestation Keys#11

Closed
iroykaufman wants to merge 2 commits intolatchset:mainfrom
iroykaufman:tpm-ak-creation
Closed

Add support for creating and persisting TPM Attestation Keys#11
iroykaufman wants to merge 2 commits intolatchset:mainfrom
iroykaufman:tpm-ak-creation

Conversation

@iroykaufman
Copy link

In some environments (e.g., GCP), the TPM is provisioned without attestation key handlers. This change adds optional support to automatically create a primary Attestation Key (AK) and persist it at a specified TPM handle.

@alicefr
Copy link
Contributor

alicefr commented Nov 7, 2025

This conflicts with the PR in ignition: coreos/ignition#2147 . The reason why in ignition is better is because if we want to implement a 2-phase attestation to protect the ignition config, this needs to run earlier then the disk encyption

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants