A way of re-provisioning (on a different OS image) that worked for me is the following:
tpm2_startup
#This clears the persistent storage
tpm2_clear
#To change profile from ECC to RSA
sed -i 's/"profile_name": "P_ECCP256SHA256"/"profile_name": "P_RSA2048SHA256"/g' /usr/local/etc/tpm2-tss/fapi-config.json
#Delete existing keystores
rm -rf ~/.local/share/tpm2-tss/user/keystore
rm -rf /usr/local/var/lib/tpm2-tss/system/keystore
#Before we provision we need to generate an EK
tpm2_createprimary -C e -g sha256 -G rsa -c endorsementprimary.ctx
tpm2_create -C endorsementprimary.ctx -g sha256 -G rsa -u rsak.pub -r rsak.priv
tpm2_load -C endorsementprimary.ctx -u rsak.pub -r rsak.priv -n rsak.name -c rsak.ctx
tpm2_evictcontrol -c rsak.ctx 0x81010001
tss2_provision
Without the tpm2_createprimary I would get an error when I use tss2_provision (something like “key cannot be signed”. I cannot remember the error message, but it contained the word EK).
Some questions that came to my mind:
Thank you very much for your comments.
Best,
Anthony
From: Anthony Arrascue
Sent: Tuesday, 1 June 2021 19:18
To: 'tpm2@lists.01.org' <tpm2@lists.01.org>
Subject: Re-provision TPM
Hello,
I am learning about the TSS and TPM techonologies.
I have provisioned the TPM with the default settings, which means I am now using the ECC profile (P_ECCP256SHA256).
However, encryption was a requirement I needed to fulfill. I just didn't
know that ECC encryption is currently not supported and now I realize RSA would be a better fit for me.
So here is my question:
Thank you for your help.
Anthony Arrascue