docs: Warn about incomplete vtpmmgr TPM 2.0 support
authorJason Andryuk <jandryuk@gmail.com>
Thu, 6 May 2021 13:59:11 +0000 (09:59 -0400)
committerAndrew Cooper <andrew.cooper3@citrix.com>
Fri, 7 May 2021 18:50:50 +0000 (19:50 +0100)
The vtpmmgr TPM 2.0 support is incomplete.  Add a warning about that to
the documentation so others don't have to work through discovering it is
broken.

Signed-off-by: Jason Andryuk <jandryuk@gmail.com>
Acked-by: Andrew Cooper <andrew.cooper3@citrix.com>
Reviewed-by: Daniel P. Smith <dpsmith@apertussolutions.com>
docs/man/xen-vtpmmgr.7.pod

index af825a7ffe44da4dbea52020b3109567bcad7cf1..875dcce5085f3791361f0fe3730dbbfbb3fca239 100644 (file)
@@ -222,6 +222,17 @@ XSM label, not the kernel.
 
 =head1 Appendix B: vtpmmgr on TPM 2.0
 
+=head2 WARNING: Incomplete - cannot persist data
+
+TPM 2.0 support for vTPM manager is incomplete.  There is no support for
+persisting an encryption key, so vTPM manager regenerates primary and secondary
+key handles each boot.
+
+Also, the vTPM manger group command implementation hardcodes TPM 1.2 commands.
+This means running manage-vtpmmgr.pl fails when the TPM 2.0 hardware rejects
+the TPM 1.2 commands.  vTPM manager with TPM 2.0 cannot create groups and
+therefore cannot persist vTPM contents.
+
 =head2 Manager disk image setup:
 
 The vTPM Manager requires a disk image to store its encrypted data. The image