4 ms·
Superficially, you should be able to make a fully compliant TPM2 on your own like this (unless I’m missing something). The one gap would be that your EK Cert wo
by strstr 4y ago
Superficially, you should be able to make a fully compliant TPM2 on your own like this (unless I’m missing something). The one gap would be that your EK Cert would have to be self signed.
- joerichey 4y agoI don't think that Windows 11 requires any sort of EK cert at all. If they did, it would require them to restrict the TPMs to a list of "approved" vendors. In this case, they bought the actual TPM2 part of the chip from Infinion, so it might already have an EK Cert on it.
- strstr 4y agoWell, that’s what I get for skimming poorly. They did just slap an off the shelf infineon chip in, so yeah, real EKcert from a legit vendor. I skimmed and had some wishful thinking that they just made a cheap off the shelf chip do the job of a TPM2 by slamming in an existing TPM2 implementation.
- Nextgrid 4y ago> I skimmed and had some wishful thinking that they just made a cheap off the shelf chip do the job of a TPM2 by slamming in an existing TPM2 implementation. Is there any evidence that it wouldn't be possible - does Windows have a list of approved EK certificate authorities it expects? The only reason I could think for this would be DRM, but I wouldn't expect this to be a requirement merely to install the OS (the un-approved TPM would still be good for any non-DRM uses, and would be useful in VMs where the TPM is already emulated by the hypervisor).
- cryptonector 4y agoYou can also run your own CA for your home-made TPMs' EKpubs.