The other workaround is to import with James Bottomley's openssl_tpm2_engine and then use it with tpm2-tss-engine.

--
dwmw2

On 7 Mar 2019 18:31, "Fuchs, Andreas" <andreas.fuchs@sit.fraunhofer.de> wrote:

Yes, X509 certificate creation works.

"Importing an existing key" however is in the backlog:
https://github.com/tpm2-software/tpm2-tss-engine/issues/39

Workaround for the moment could be to temporarily evictControl the key to persistent.

Otherwise sorry to keep you waiting for the moment.
________________________________________
From: Roberts, William C [william.c.roberts@intel.com]
Sent: Thursday, March 07, 2019 19:26
To: tpm2@lists.01.org
Cc: Fuchs, Andreas
Subject: using existing key with tpm2-tss-engine

Is there a way to use an existing key with the engine? Ie existing key to pem file?

I am not seeing a mechanism for this.

My use case:
I need to solve issue:
https://github.com/tpm2-software/tpm2-pkcs11/issues/16

So I can store the X509 certificate for a key in the attributes.

Looks like cert creation is tested a bit in:
test/sserver.sh


Bill
_______________________________________________
tpm2 mailing list
tpm2@lists.01.org
https://lists.01.org/mailman/listinfo/tpm2