// Copyright (C) 2015 The Android Open Source Project
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// See the License for the specific language governing permissions and
// limitations under the License.
#include <string>
#include <base/macros.h>
#include <trousers/tss.h>
#include <trousers/trousers.h> // NOLINT(build/include_alpha)
#include "tpm_manager/server/openssl_crypto_util_impl.h"
#include "tpm_manager/server/tpm_connection.h"
#include "tpm_manager/server/tpm_initializer.h"
namespace tpm_manager {
class LocalDataStore;
class TpmStatus;
// This class initializes a Tpm1.2 chip by taking ownership. Example use of
// this class is:
// LocalDataStore data_store;
// TpmStatusImpl status;
// TpmInitializerImpl initializer(&data_store, &status);
// initializer.InitializeTpm();
// If the tpm is unowned, InitializeTpm injects a random owner password,
// initializes and unrestricts the SRK, and persists the owner password to disk
// until all the owner dependencies are satisfied.
class TpmInitializerImpl : public TpmInitializer {
// Does not take ownership of |local_data_store| or |tpm_status|.
TpmInitializerImpl(LocalDataStore* local_data_store, TpmStatus* tpm_status);
~TpmInitializerImpl() override = default;
// TpmInitializer methods.
bool InitializeTpm() override;
bool PreInitializeTpm() override;
void VerifiedBootHelper() override;
bool ResetDictionaryAttackLock() override;
// This method checks if an EndorsementKey exists on the Tpm and creates it
// if not. Returns true on success, else false. The |connection| already has
// the owner password injected.
bool InitializeEndorsementKey(TpmConnection* connection);
// This method takes ownership of the Tpm with the default TSS password.
// Returns true on success, else false. The |connection| already has the
// default owner password injected.
bool TakeOwnership(TpmConnection* connection);
// This method initializes the SRK if it does not exist, zero's the SRK
// password and unrestricts its usage. Returns true on success, else false.
// The |connection| already has the current owner password injected.
bool InitializeSrk(TpmConnection* connection);
// This method changes the Tpm owner password from the default TSS password
// to the password provided in the |owner_password| argument.
// Returns true on success, else false. The |connection| already has the old
// owner password injected.
bool ChangeOwnerPassword(TpmConnection* connection,
const std::string& owner_password);
// This method return true iff the provided |owner_password| is the current
// owner password in the Tpm. This method can also return false if there was
// an error communicating with the Tpm.
bool TestTpmAuth(const std::string& owner_password);
OpensslCryptoUtilImpl openssl_util_;
LocalDataStore* local_data_store_;
TpmStatus* tpm_status_;
} // namespace tpm_manager