A way of re-provisioning (on a different OS image) that worked for me is the following:

 

tpm2_startup

#This clears the persistent storage

tpm2_clear

#To change profile from ECC to RSA

sed -i 's/"profile_name": "P_ECCP256SHA256"/"profile_name": "P_RSA2048SHA256"/g' /usr/local/etc/tpm2-tss/fapi-config.json

#Delete existing keystores

rm -rf ~/.local/share/tpm2-tss/user/keystore

rm -rf /usr/local/var/lib/tpm2-tss/system/keystore

#Before we provision we need to generate an EK

tpm2_createprimary -C e -g sha256 -G rsa -c endorsementprimary.ctx

tpm2_create -C endorsementprimary.ctx -g sha256 -G rsa -u rsak.pub -r rsak.priv

tpm2_load -C endorsementprimary.ctx -u rsak.pub -r rsak.priv -n rsak.name -c rsak.ctx

tpm2_evictcontrol -c rsak.ctx 0x81010001

tss2_provision

 

Without the tpm2_createprimary I would get an error when I use tss2_provision (something like “key cannot be signed”. I cannot remember the error message, but it contained the word EK).

 

Some questions that came to my mind:

  1. Can all of this be done using only Fapi (no tpm2 commands)
  2. Why is generating an EK required for provisioning? (which documentation describes this step)
  3. Previous versions of the tpm2-tools had also a tpm2_takeownership. What happened with it and how to provision with owner’s authorization?

 

Thank you very much for your comments.

Best,

Anthony

 

 

 

 

 

From: Anthony Arrascue
Sent: Tuesday, 1 June 2021 19:18
To: 'tpm2@lists.01.org' <tpm2@lists.01.org>
Subject: Re-provision TPM

 

Hello,

 

I am learning about the TSS and TPM techonologies.
I have provisioned the TPM with the default settings, which means I am now using the ECC profile (P_ECCP256SHA256).

However, encryption was a requirement I needed to fulfill. I just didn't know that ECC encryption is currently not supported and now I realize RSA would be a better fit for me.

So here is my question:

Thank you for your help.

Anthony Arrascue