Esys_CertifyCreation.3 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. .TH "Esys_CertifyCreation" 3 "Fri Oct 7 2022" "Version 3.2.0" "tpm2-tss" \" -*- nroff -*-
  2. .ad l
  3. .nh
  4. .SH NAME
  5. Esys_CertifyCreation
  6. .SH SYNOPSIS
  7. .br
  8. .PP
  9. .SS "Functions"
  10. .in +1c
  11. .ti -1c
  12. .RI "TSS2_RC \fBEsys_CertifyCreation_Async\fP (\fBESYS_CONTEXT\fP *esysContext, \fBESYS_TR\fP signHandle, \fBESYS_TR\fP objectHandle, \fBESYS_TR\fP shandle1, \fBESYS_TR\fP shandle2, \fBESYS_TR\fP shandle3, const TPM2B_DATA *qualifyingData, const TPM2B_DIGEST *creationHash, const TPMT_SIG_SCHEME *inScheme, const TPMT_TK_CREATION *creationTicket)"
  13. .br
  14. .ti -1c
  15. .RI "TSS2_RC \fBEsys_CertifyCreation\fP (\fBESYS_CONTEXT\fP *esysContext, \fBESYS_TR\fP signHandle, \fBESYS_TR\fP objectHandle, \fBESYS_TR\fP shandle1, \fBESYS_TR\fP shandle2, \fBESYS_TR\fP shandle3, const TPM2B_DATA *qualifyingData, const TPM2B_DIGEST *creationHash, const TPMT_SIG_SCHEME *inScheme, const TPMT_TK_CREATION *creationTicket, TPM2B_ATTEST **certifyInfo, TPMT_SIGNATURE **signature)"
  16. .br
  17. .ti -1c
  18. .RI "TSS2_RC \fBEsys_CertifyCreation_Finish\fP (\fBESYS_CONTEXT\fP *esysContext, TPM2B_ATTEST **certifyInfo, TPMT_SIGNATURE **signature)"
  19. .br
  20. .in -1c
  21. .SH "Detailed Description"
  22. .PP
  23. ESAPI function to invoke the TPM2_CertifyCreation command either as a one-call or in an asynchronous manner\&.
  24. .SH "Function Documentation"
  25. .PP
  26. .SS "TSS2_RC Esys_CertifyCreation (\fBESYS_CONTEXT\fP * esysContext, \fBESYS_TR\fP signHandle, \fBESYS_TR\fP objectHandle, \fBESYS_TR\fP shandle1, \fBESYS_TR\fP shandle2, \fBESYS_TR\fP shandle3, const TPM2B_DATA * qualifyingData, const TPM2B_DIGEST * creationHash, const TPMT_SIG_SCHEME * inScheme, const TPMT_TK_CREATION * creationTicket, TPM2B_ATTEST ** certifyInfo, TPMT_SIGNATURE ** signature)"
  27. One-Call function for TPM2_CertifyCreation
  28. .PP
  29. This function invokes the TPM2_CertifyCreation command in a one-call variant\&. This means the function will block until the TPM response is available\&. All input parameters are const\&. The memory for non-simple output parameters is allocated by the function implementation\&.
  30. .PP
  31. \fBParameters:\fP
  32. .RS 4
  33. \fIesysContext\fP The \fBESYS_CONTEXT\fP\&.
  34. .br
  35. \fIsignHandle\fP Handle of the key that will sign the attestation block\&.
  36. .br
  37. \fIobjectHandle\fP The object associated with the creation data\&.
  38. .br
  39. \fIshandle1\fP Session handle for authorization of signHandle
  40. .br
  41. \fIshandle2\fP Second session handle\&.
  42. .br
  43. \fIshandle3\fP Third session handle\&.
  44. .br
  45. \fIqualifyingData\fP User-provided qualifying data\&.
  46. .br
  47. \fIcreationHash\fP Hash of the creation data produced by TPM2_Create() or TPM2_CreatePrimary()\&.
  48. .br
  49. \fIinScheme\fP TPM2_Signing scheme to use if the scheme for signHandle is TPM2_ALG_NULL\&.
  50. .br
  51. \fIcreationTicket\fP Ticket produced by TPM2_Create() or TPM2_CreatePrimary()\&.
  52. .br
  53. \fIcertifyInfo\fP The structure that was signed\&. (callee-allocated)
  54. .br
  55. \fIsignature\fP The signature over certifyInfo \&. (callee-allocated)
  56. .RE
  57. .PP
  58. \fBReturn values:\fP
  59. .RS 4
  60. \fITSS2_RC_SUCCESS\fP if the function call was a success\&.
  61. .br
  62. \fITSS2_ESYS_RC_BAD_REFERENCE\fP if the esysContext or required input pointers or required output handle references are NULL\&.
  63. .br
  64. \fITSS2_ESYS_RC_BAD_CONTEXT\fP if esysContext corruption is detected\&.
  65. .br
  66. \fITSS2_ESYS_RC_MEMORY\fP if the ESAPI cannot allocate enough memory for internal operations or return parameters\&.
  67. .br
  68. \fITSS2_ESYS_RC_BAD_SEQUENCE\fP if the context has an asynchronous operation already pending\&.
  69. .br
  70. \fITSS2_ESYS_RC_INSUFFICIENT_RESPONSE\fP if the TPM's response does not at least contain the tag, response length, and response code\&.
  71. .br
  72. \fITSS2_ESYS_RC_MALFORMED_RESPONSE\fP if the TPM's response is corrupted\&.
  73. .br
  74. \fITSS2_ESYS_RC_RSP_AUTH_FAILED\fP if the response HMAC from the TPM did not verify\&.
  75. .br
  76. \fITSS2_ESYS_RC_MULTIPLE_DECRYPT_SESSIONS\fP if more than one session has the 'decrypt' attribute bit set\&.
  77. .br
  78. \fITSS2_ESYS_RC_MULTIPLE_ENCRYPT_SESSIONS\fP if more than one session has the 'encrypt' attribute bit set\&.
  79. .br
  80. \fITSS2_ESYS_RC_BAD_TR\fP if any of the ESYS_TR objects are unknown to the \fBESYS_CONTEXT\fP or are of the wrong type or if required ESYS_TR objects are ESYS_TR_NONE\&.
  81. .br
  82. \fITSS2_RCs\fP produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally\&.
  83. .RE
  84. .PP
  85. .SS "TSS2_RC Esys_CertifyCreation_Async (\fBESYS_CONTEXT\fP * esysContext, \fBESYS_TR\fP signHandle, \fBESYS_TR\fP objectHandle, \fBESYS_TR\fP shandle1, \fBESYS_TR\fP shandle2, \fBESYS_TR\fP shandle3, const TPM2B_DATA * qualifyingData, const TPM2B_DIGEST * creationHash, const TPMT_SIG_SCHEME * inScheme, const TPMT_TK_CREATION * creationTicket)"
  86. Asynchronous function for TPM2_CertifyCreation
  87. .PP
  88. This function invokes the TPM2_CertifyCreation command in a asynchronous variant\&. This means the function will return as soon as the command has been sent downwards the stack to the TPM\&. All input parameters are const\&. In order to retrieve the TPM's response call Esys_CertifyCreation_Finish\&.
  89. .PP
  90. \fBParameters:\fP
  91. .RS 4
  92. \fIesysContext\fP The \fBESYS_CONTEXT\fP\&.
  93. .br
  94. \fIsignHandle\fP Handle of the key that will sign the attestation block\&.
  95. .br
  96. \fIobjectHandle\fP The object associated with the creation data\&.
  97. .br
  98. \fIshandle1\fP Session handle for authorization of signHandle
  99. .br
  100. \fIshandle2\fP Second session handle\&.
  101. .br
  102. \fIshandle3\fP Third session handle\&.
  103. .br
  104. \fIqualifyingData\fP User-provided qualifying data\&.
  105. .br
  106. \fIcreationHash\fP Hash of the creation data produced by TPM2_Create() or TPM2_CreatePrimary()\&.
  107. .br
  108. \fIinScheme\fP TPM2_Signing scheme to use if the scheme for signHandle is TPM2_ALG_NULL\&.
  109. .br
  110. \fIcreationTicket\fP Ticket produced by TPM2_Create() or TPM2_CreatePrimary()\&.
  111. .RE
  112. .PP
  113. \fBReturn values:\fP
  114. .RS 4
  115. \fIESYS_RC_SUCCESS\fP if the function call was a success\&.
  116. .br
  117. \fITSS2_ESYS_RC_BAD_REFERENCE\fP if the esysContext or required input pointers or required output handle references are NULL\&.
  118. .br
  119. \fITSS2_ESYS_RC_BAD_CONTEXT\fP if esysContext corruption is detected\&.
  120. .br
  121. \fITSS2_ESYS_RC_MEMORY\fP if the ESAPI cannot allocate enough memory for internal operations or return parameters\&.
  122. .br
  123. \fITSS2_RCs\fP produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally\&.
  124. .br
  125. \fITSS2_ESYS_RC_MULTIPLE_DECRYPT_SESSIONS\fP if more than one session has the 'decrypt' attribute bit set\&.
  126. .br
  127. \fITSS2_ESYS_RC_MULTIPLE_ENCRYPT_SESSIONS\fP if more than one session has the 'encrypt' attribute bit set\&.
  128. .br
  129. \fITSS2_ESYS_RC_BAD_TR\fP if any of the ESYS_TR objects are unknown to the \fBESYS_CONTEXT\fP or are of the wrong type or if required ESYS_TR objects are ESYS_TR_NONE\&.
  130. .RE
  131. .PP
  132. .SS "TSS2_RC Esys_CertifyCreation_Finish (\fBESYS_CONTEXT\fP * esysContext, TPM2B_ATTEST ** certifyInfo, TPMT_SIGNATURE ** signature)"
  133. Asynchronous finish function for TPM2_CertifyCreation
  134. .PP
  135. This function returns the results of a TPM2_CertifyCreation command invoked via Esys_CertifyCreation_Finish\&. All non-simple output parameters are allocated by the function's implementation\&. NULL can be passed for every output parameter if the value is not required\&.
  136. .PP
  137. \fBParameters:\fP
  138. .RS 4
  139. \fIesysContext\fP The \fBESYS_CONTEXT\fP\&.
  140. .br
  141. \fIcertifyInfo\fP The structure that was signed\&. (callee-allocated)
  142. .br
  143. \fIsignature\fP The signature over certifyInfo \&. (callee-allocated)
  144. .RE
  145. .PP
  146. \fBReturn values:\fP
  147. .RS 4
  148. \fITSS2_RC_SUCCESS\fP on success
  149. .br
  150. \fIESYS_RC_SUCCESS\fP if the function call was a success\&.
  151. .br
  152. \fITSS2_ESYS_RC_BAD_REFERENCE\fP if the esysContext or required input pointers or required output handle references are NULL\&.
  153. .br
  154. \fITSS2_ESYS_RC_BAD_CONTEXT\fP if esysContext corruption is detected\&.
  155. .br
  156. \fITSS2_ESYS_RC_MEMORY\fP if the ESAPI cannot allocate enough memory for internal operations or return parameters\&.
  157. .br
  158. \fITSS2_ESYS_RC_BAD_SEQUENCE\fP if the context has an asynchronous operation already pending\&.
  159. .br
  160. \fITSS2_ESYS_RC_TRY_AGAIN\fP if the timeout counter expires before the TPM response is received\&.
  161. .br
  162. \fITSS2_ESYS_RC_INSUFFICIENT_RESPONSE\fP if the TPM's response does not at least contain the tag, response length, and response code\&.
  163. .br
  164. \fITSS2_ESYS_RC_RSP_AUTH_FAILED\fP if the response HMAC from the TPM did not verify\&.
  165. .br
  166. \fITSS2_ESYS_RC_MALFORMED_RESPONSE\fP if the TPM's response is corrupted\&.
  167. .br
  168. \fITSS2_RCs\fP produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally\&.
  169. .RE
  170. .PP
  171. .SH "Author"
  172. .PP
  173. Generated automatically by Doxygen for tpm2-tss from the source code\&.