summaryrefslogtreecommitdiff
path: root/man/man3/Tspi_TPM_CMKSetRestrictions.3
diff options
context:
space:
mode:
authorIgor Pashev <pashev.igor@gmail.com>2012-11-25 14:36:20 +0000
committerIgor Pashev <pashev.igor@gmail.com>2012-11-25 14:36:20 +0000
commitc3649a2def02c41d837ae1f79dda729ccb91e677 (patch)
treebea46dff212fdef977fe9094a70a939e8cc21885 /man/man3/Tspi_TPM_CMKSetRestrictions.3
downloadtrousers-upstream.tar.gz
Imported Upstream version 0.3.9upstream/0.3.9upstream
Diffstat (limited to 'man/man3/Tspi_TPM_CMKSetRestrictions.3')
-rw-r--r--man/man3/Tspi_TPM_CMKSetRestrictions.393
1 files changed, 93 insertions, 0 deletions
diff --git a/man/man3/Tspi_TPM_CMKSetRestrictions.3 b/man/man3/Tspi_TPM_CMKSetRestrictions.3
new file mode 100644
index 0000000..1b233d4
--- /dev/null
+++ b/man/man3/Tspi_TPM_CMKSetRestrictions.3
@@ -0,0 +1,93 @@
+.\" Copyright (C) 2007 International Business Machines Corporation
+.\"
+.de Sh \" Subsection
+.br
+.if t .Sp
+.ne 5
+.PP
+\fB\\$1\fR
+.PP
+..
+.de Sp \" Vertical space (when we can't use .PP)
+.if t .sp .5v
+.if n .sp
+..
+.de Ip \" List item
+.br
+.ie \\n(.$>=3 .ne \\$3
+.el .ne 3
+.IP "\\$1" \\$2
+..
+.TH "Tspi_TPM_CMKSetRestrictions" 3 "2007-12-13" "TSS 1.2"
+.ce 1
+TCG Software Stack Developer's Reference
+.SH NAME
+Tspi_TPM_CMKSetRestrictions \- set restrictions on use of delegated Certified Migratable Keys
+.SH "SYNOPSIS"
+.ad l
+.hy 0
+.nf
+.B #include <tss/tspi.h>
+.sp
+.BI "TSS_RESULT Tspi_TPM_CMKSetRestrictions(TSS_HTPM " hTPM ", TSS_CMK_DELEGATE " CmkDelegate ");"
+.fi
+.sp
+.ad
+.hy
+
+.SH "DESCRIPTION"
+.PP
+\fBTspi_TPM_CMKSetRestrictions\fR is used to set restrictions on the delegated use of Certified Migratable Keys (CMKs). Use of this command cannot itself be delegated.
+
+.SH "PARAMETERS"
+.PP
+.SS hTPM
+The \fIhTPM\fR parameter is used to specify the handle of the TPM object.
+.SS CmkDelegate
+The \fICmkDelegate\fR parameter is a bitmask describing the kinds of CMKs that can be used in a delegated auth session. Each bit represents a type of key. If the bit of a key type is set, then the CMK can be used in a delegated authorization session, otherwise use of that key will result in a TPM_E_INVALID_KEYUSAGE return code from the TPM.
+
+The possible values of \fICmkDelegate\fR are any combination of the following flags logically OR'd together:
+
+.TP
+.SM "TSS_CMK_DELEGATE_SIGNING"
+Allow use of signing keys.
+
+.TP
+.SM "TSS_CMK_DELEGATE_STORAGE"
+Allow use of storage keys.
+
+.TP
+.SM "TSS_CMK_DELEGATE_BIND"
+Allow use of binding keys.
+
+.TP
+.SM "TSS_CMK_DELEGATE_LEGACY"
+Allow use of legacy keys.
+
+.TP
+.SM "TSS_CMK_DELEGATE_MIGRATE"
+Allow use of migratable keys.
+
+.SH "RETURN CODES"
+.PP
+\fBTspi_TPM_CMKSetRestrictions\fR returns TSS_SUCCESS on success, otherwise one of the
+following values is returned:
+.TP
+.SM TSS_E_INVALID_HANDLE
+\fIhTPM\fR is not a valid handle.
+
+.TP
+.SM TSS_E_INTERNAL_ERROR
+An internal SW error has been detected.
+
+.SH "CONFORMING TO"
+
+.PP
+\fBTspi_TPM_CMKSetRestrictions\fR conforms to the Trusted Computing Group
+Software Specification version 1.2 Errata A
+
+.SH "SEE ALSO"
+
+.PP
+\fBTspi_TPM_CMKApproveMA\fR(3), \fBTspi_TPM_CMKCreateTicket\fR(3), \fBTspi_Key_CMKCreateBlob\fR(3)
+