Fapi_Provision.3 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191
  1. .TH "Fapi_Provision" 3 "Fri Oct 7 2022" "Version 3.2.0" "tpm2-tss" \" -*- nroff -*-
  2. .ad l
  3. .nh
  4. .SH NAME
  5. Fapi_Provision
  6. .SH SYNOPSIS
  7. .br
  8. .PP
  9. .SS "Functions"
  10. .in +1c
  11. .ti -1c
  12. .RI "TSS2_RC \fBFapi_Provision\fP (\fBFAPI_CONTEXT\fP *context, char const *authValueEh, char const *authValueSh, char const *authValueLockout)"
  13. .br
  14. .ti -1c
  15. .RI "TSS2_RC \fBFapi_Provision_Async\fP (\fBFAPI_CONTEXT\fP *context, char const *authValueEh, char const *authValueSh, char const *authValueLockout)"
  16. .br
  17. .ti -1c
  18. .RI "TSS2_RC \fBFapi_Provision_Finish\fP (\fBFAPI_CONTEXT\fP *context)"
  19. .br
  20. .in -1c
  21. .SH "Detailed Description"
  22. .PP
  23. FAPI functions to invoke Provision either as one-call or in an asynchronous manner\&.
  24. .SH "Function Documentation"
  25. .PP
  26. .SS "Fapi_Provision (\fBFAPI_CONTEXT\fP * context, char const * authValueEh, char const * authValueSh, char const * authValueLockout)"
  27. One-Call function for the initial FAPI provisioning\&.
  28. .PP
  29. Provisions a TSS with its TPM\&. This includes the setting of important passwords and policy settings as well as the readout of the EK and its certificate and the initialization of the system-wide keystore\&.
  30. .PP
  31. \fBParameters:\fP
  32. .RS 4
  33. \fIcontext\fP The \fBFAPI_CONTEXT\fP\&.
  34. .br
  35. \fIauthValueEh\fP The authorization value for the endorsement hierarchy\&. May be NULL
  36. .br
  37. \fIauthValueSh\fP The authorization value for the storage hierarchy\&. Should be NULL
  38. .br
  39. \fIauthValueLockout\fP The authorization value for lockout\&.
  40. .RE
  41. .PP
  42. \fBReturn values:\fP
  43. .RS 4
  44. \fITSS2_RC_SUCCESS\fP if the function call was a success\&.
  45. .br
  46. \fITSS2_FAPI_RC_BAD_REFERENCE\fP if context is NULL\&.
  47. .br
  48. \fITSS2_FAPI_RC_BAD_CONTEXT\fP if context corruption is detected\&.
  49. .br
  50. \fITSS2_FAPI_RC_BAD_SEQUENCE\fP if the context has an asynchronous operation already pending\&.
  51. .br
  52. \fITSS2_FAPI_RC_NO_CERT\fP if no certificate was found for the computed EK\&.
  53. .br
  54. \fITSS2_FAPI_RC_BAD_KEY\fP if public key of the EK does not match the configured certificate or the configured fingerprint does not match the computed EK\&.
  55. .br
  56. \fITSS2_FAPI_RC_IO_ERROR\fP if the data cannot be saved\&.
  57. .br
  58. \fITSS2_FAPI_RC_MEMORY\fP if the FAPI cannot allocate enough memory for internal operations or return parameters\&.
  59. .br
  60. \fITSS2_FAPI_RC_NO_TPM\fP if FAPI was initialized in no-TPM-mode via its config file\&.
  61. .br
  62. \fITSS2_FAPI_RC_TRY_AGAIN\fP if an I/O operation is not finished yet and this function needs to be called again\&.
  63. .br
  64. \fITSS2_FAPI_RC_BAD_VALUE\fP if an invalid value was passed into the function\&.
  65. .br
  66. \fITSS2_FAPI_RC_AUTHORIZATION_UNKNOWN\fP if a required authorization callback is not set\&.
  67. .br
  68. \fITSS2_FAPI_RC_AUTHORIZATION_FAILED\fP if the authorization attempt fails\&.
  69. .br
  70. \fITSS2_FAPI_RC_GENERAL_FAILURE\fP if an internal error occurred\&.
  71. .br
  72. \fITSS2_FAPI_RC_POLICY_UNKNOWN\fP if policy search for a certain policy digest was not successful\&.
  73. .br
  74. \fITSS2_FAPI_RC_PATH_NOT_FOUND\fP if a FAPI object path was not found during authorization\&.
  75. .br
  76. \fITSS2_FAPI_RC_KEY_NOT_FOUND\fP if a key was not found\&.
  77. .br
  78. \fITSS2_ESYS_RC_*\fP possible error codes of ESAPI\&.
  79. .br
  80. \fITSS2_FAPI_RC_BAD_PATH\fP if the path is used in inappropriate context or contains illegal characters\&.
  81. .br
  82. \fITSS2_FAPI_RC_NOT_PROVISIONED\fP FAPI was not provisioned\&.
  83. .br
  84. \fITSS2_FAPI_RC_PATH_ALREADY_EXISTS\fP if the object already exists in object store\&.
  85. .RE
  86. .PP
  87. .SS "Fapi_Provision_Async (\fBFAPI_CONTEXT\fP * context, char const * authValueEh, char const * authValueSh, char const * authValueLockout)"
  88. Asynchronous function for the initial FAPI provisioning\&.
  89. .PP
  90. Provisions a TSS with its TPM\&. This includes the setting of important passwords and policy settings as well as the readout of the EK and its certificate and the initialization of the system-wide keystore\&.
  91. .PP
  92. Call Fapi_Provision_Finish to finish the execution of this command\&.
  93. .PP
  94. \fBParameters:\fP
  95. .RS 4
  96. \fIcontext\fP The \fBFAPI_CONTEXT\fP\&.
  97. .br
  98. \fIauthValueEh\fP The authorization value for the endorsement hierarchy\&. May be NULL
  99. .br
  100. \fIauthValueSh\fP The authorization value for the storage hierarchy\&. Should be NULL
  101. .br
  102. \fIauthValueLockout\fP The authorization value for lockout\&.
  103. .RE
  104. .PP
  105. \fBReturn values:\fP
  106. .RS 4
  107. \fITSS2_RC_SUCCESS\fP if the function call was a success\&.
  108. .br
  109. \fITSS2_FAPI_RC_BAD_REFERENCE\fP if context is NULL\&.
  110. .br
  111. \fITSS2_FAPI_RC_BAD_CONTEXT\fP if context corruption is detected\&.
  112. .br
  113. \fITSS2_FAPI_RC_BAD_SEQUENCE\fP if the context has an asynchronous operation already pending\&.
  114. .br
  115. \fITSS2_FAPI_RC_IO_ERROR\fP if the data cannot be saved\&.
  116. .br
  117. \fITSS2_FAPI_RC_MEMORY\fP if the FAPI cannot allocate enough memory for internal operations or return parameters\&.
  118. .br
  119. \fITSS2_FAPI_RC_NO_TPM\fP if FAPI was initialized in no-TPM-mode via its config file\&.
  120. .br
  121. \fITSS2_FAPI_RC_BAD_VALUE\fP if an invalid value was passed into the function\&.
  122. .br
  123. \fITSS2_FAPI_RC_BAD_PATH\fP if the path is used in inappropriate context or contains illegal characters\&.
  124. .br
  125. \fITSS2_FAPI_RC_PATH_NOT_FOUND\fP if a FAPI object path was not found during authorization\&.
  126. .RE
  127. .PP
  128. .SS "Fapi_Provision_Finish (\fBFAPI_CONTEXT\fP * context)"
  129. Asynchronous finish function for Fapi_Provision
  130. .PP
  131. This function should be called after a previous Fapi_Provision_Async\&.
  132. .PP
  133. \fBParameters:\fP
  134. .RS 4
  135. \fIcontext\fP The \fBFAPI_CONTEXT\fP
  136. .RE
  137. .PP
  138. \fBReturn values:\fP
  139. .RS 4
  140. \fITSS2_RC_SUCCESS\fP if the function call was a success\&.
  141. .br
  142. \fITSS2_FAPI_RC_BAD_REFERENCE\fP if context is NULL\&.
  143. .br
  144. \fITSS2_FAPI_RC_BAD_CONTEXT\fP if context corruption is detected\&.
  145. .br
  146. \fITSS2_FAPI_RC_BAD_SEQUENCE\fP if the context has an asynchronous operation already pending\&.
  147. .br
  148. \fITSS2_FAPI_RC_NO_CERT\fP if no certificate was found for the computed EK\&.
  149. .br
  150. \fITSS2_FAPI_RC_BAD_KEY\fP if public key of the EK does not match the configured certificate or the configured fingerprint does not match the computed EK\&.
  151. .br
  152. \fITSS2_FAPI_RC_IO_ERROR\fP if the data cannot be saved\&.
  153. .br
  154. \fITSS2_FAPI_RC_MEMORY\fP if the FAPI cannot allocate enough memory for internal operations or return parameters\&.
  155. .br
  156. \fITSS2_FAPI_RC_TRY_AGAIN\fP if the asynchronous operation is not yet complete\&. Call this function again later\&.
  157. .br
  158. \fITSS2_FAPI_RC_BAD_VALUE\fP if an invalid value was passed into the function\&.
  159. .br
  160. \fITSS2_FAPI_RC_AUTHORIZATION_UNKNOWN\fP if a required authorization callback is not set\&.
  161. .br
  162. \fITSS2_FAPI_RC_AUTHORIZATION_FAILED\fP if the authorization attempt fails\&.
  163. .br
  164. \fITSS2_FAPI_RC_GENERAL_FAILURE\fP if an internal error occurred\&.
  165. .br
  166. \fITSS2_FAPI_RC_POLICY_UNKNOWN\fP if policy search for a certain policy digest was not successful\&.
  167. .br
  168. \fITSS2_FAPI_RC_PATH_NOT_FOUND\fP if a FAPI object path was not found during authorization\&.
  169. .br
  170. \fITSS2_FAPI_RC_KEY_NOT_FOUND\fP if a key was not found\&.
  171. .br
  172. \fITSS2_ESYS_RC_*\fP possible error codes of ESAPI\&.
  173. .br
  174. \fITSS2_FAPI_RC_NOT_PROVISIONED\fP FAPI was not provisioned\&.
  175. .br
  176. \fITSS2_FAPI_RC_BAD_PATH\fP if the path is used in inappropriate context or contains illegal characters\&.
  177. .br
  178. \fITSS2_FAPI_RC_PATH_ALREADY_EXISTS\fP if the object already exists in object store\&.
  179. .RE
  180. .PP
  181. < Certificates will be stored at even address
  182. .PP
  183. < RSA template
  184. .PP
  185. < ECC template
  186. .SH "Author"
  187. .PP
  188. Generated automatically by Doxygen for tpm2-tss from the source code\&.