The AIK-requests to the PrivacyCA are NOT signed via the EK. Instead the replies of the PrivacyCA to the TPM (containing the Certificate) are encrypted for the EK.
Ugh. Yup, that's an obvious mistake. Thanks for the correction!
The AIK-requests to the PrivacyCA are NOT signed via the EK. Instead the replies of the PrivacyCA to the TPM (containing the Certificate) are encrypted for the EK.
Power management, mobile and firmware developer on Linux. Security developer at nvidia. Ex-biologist. Content here should not be interpreted as the opinion of my employer. Also on Mastodon and Bluesky.
Re: AIK PrivacyCA interaction
Date: 2013-05-08 02:10 pm (UTC)Ugh. Yup, that's an obvious mistake. Thanks for the correction!
That's something for me to look into. Thanks!