Yes, X509 certificate creation works.
"Importing an existing key" however is in the backlog:
https://github.com/tpm2-software/tpm2-tss-engine/issues/39
Workaround for the moment could be to temporarily evictControl the key to persistent.
Otherwise sorry to keep you waiting for the moment.
________________________________________
From: Roberts, William C [william.c.roberts@intel.com]
Sent: Thursday, March 07, 2019 19:26
To: tpm2@lists.01.org
Cc: Fuchs, Andreas
Subject: using existing key with tpm2-tss-engine
Is there a way to use an existing key with the engine? Ie existing key to pem file?
I am not seeing a mechanism for this.
My use case:
I need to solve issue:
https://github.com/tpm2-software/tpm2-pkcs11/issues/16
So I can store the X509 certificate for a key in the attributes.
Looks like cert creation is tested a bit in:
test/sserver.sh
Bill
_______________________________________________
tpm2 mailing list
tpm2@lists.01.org
https://lists.01.org/mailman/listinfo/tpm2