Moving subkey to TPM fails

Maxime Ripard maxime at cerno.tech
Thu May 26 18:38:02 CEST 2022


Hi,

I've been trying to setup two NIST P256 signing key and authorization
key into the TPM of a laptop I just received.

I generated the subkeys, but when running keytotpm, it fails with:

error from TPM: Not supported

The NIST P256 algorithm seems to be supported though, since it's
mandatory in the TPM2 spec as far as I'm aware, and the TPM reports it
as supported anyway:

$ tpm2_getcap ecc-curves
TPM2_ECC_NIST_P256: 0x3
TPM2_ECC_NIST_P384: 0x4

Is there any way to debug this further?

Thanks!
Maxime
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20220526/93bff2ff/attachment.sig>


More information about the Gnupg-users mailing list