Skip to content
3.1.0
Compare
Choose a tag to compare

[3.1.0] - 2021-05-17

Fixed

  • Fixed possible access outside the array in ifapi_calculate_tree.
  • Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly
    Note: that all TPM object created with a PolicyPCR with the currentPcrs
    and currentPcrsAndBank options have been created with an incorrect policy
    that ommits PCR checks. All these objects have to be recreated!
  • Fixed segfault in Fapi_Finalize where a free of a constant string could occur.
  • Fixed binding to ESYS_TR_RH_NULL for ESYS auth sessions.
  • Fixed read eagain error handling for freeBSD.
  • Fixed error cleanup for key loading and policy execution.
  • Fixed initialization of default log_dir.
  • Fixed cleanup in several error cases in Fapi.
  • Added initialise 'out' parameter in ifapi_json_IFAPI_CONFIG_deserialize.
  • Fixed Regression in Fapi_List.
  • Fixed memory leak in policy calculation.
  • Fixed setting of the system flag of NV objects:
    This will let NV object metadata be created system-wide always instead of
    locally in the user. Existing metadata will remain in the user directory.
    It can be moved to the corresponding systemstore manually if needed.
  • Fixed fapi policy searching, when a policyRef was provided.
  • Fapi accepts EK-Certs without CRL dist point.
  • Fixed bad return codes in Fapi_List.
  • Fixed memleak in Fapi policy execution.
  • Fixed coverity NULL-pointer check in Fapi.
  • Fixed the written flag of NV objects in FAPI PolicyNV commands being unset.
  • Fixed deleting of policy files.
  • Fixed wrong file loading during object search.
  • Fixed a memory leak in async keystore load.
  • Fixed bug in FAPI NV creation with custom index values.
  • Fixed leftover sessions in error cases in FAPI.
  • Fixed execution of FAPI policies in some cases.
  • Fixed handling 0x hex prefixes for TPMU_HA in JSON encoding.
  • Fixed fix doxygen header of function iesys_update_session_flags.
  • Fixed issue where nonceTPM was included twice in HMAC.
  • Fixed issue of unused variable when enabling lower default log levels.
  • Fixed 'partial' may be used uninitialized in tcti-device.

Added

  • Added two new TPM commands TPM2_CC_CertifyX509 and TPM2_CC_ACT_SetTimeout
    along with SYS and ESYS API calls, new structures definitions, and marshal
    funtions for them. This make the TSS2 alligned with TPM2 1.59 specification.
  • Support for auth values larger than an objects nameAlg for NV and key objects.
  • Async mode of operation for mssim TCTI module
  • Added pcap TCTI.
  • Added GlobalSign TPM Root CA certs to FAPI cert store.
  • Added support for auth value sizes bigger than the size of the name hash alg.
    for keys and NV objects.
  • Added better error messages in several FAPI errors.
  • Added checks to FAPI policy paths.
  • Added checks if FAPI is correctly provisioned.

Changed

  • Changed CI from Travis to GH actions
  • Changed the default hash algorithm from sha1 to sha256 in all FAPI
    integration tests
  • Changed tests to use SHA256 over SHA1.
  • Changed EncryptDecrypt mode type to align with TPM2.0 spec 1.59.
3.0.4
Compare
Choose a tag to compare

[3.0.4] - 2021-05-17

Changed or Fixed

  • Fixed possible access outside the array in ifapi_calculate_tree.
  • Fixed make install on systems without systemd
  • Fixed segfault in Fapi_Finalize where a free of a constant string could occur.
  • Fixed binding to ESYS_TR_RH_NULL for ESYS auth sessions.
  • Fixed read eagain error handling for freeBSD.
  • Fixed potential memory corruption in Fapi_Import.
  • Fixed binding of ESYS_TR_RH_NULL (Fixes #1993)
  • Added initialise 'out' parameter in ifapi_json_IFAPI_CONFIG_deserialize.
  • Fixed cleanup in several error cases.
  • Fixed initialization of default log_dir.
  • Fixed error cleanup for key loading and policy execution.
  • Fixed state handling in policy execution.
  • Fixed determination of object type from path.
  • Fixed fix doxygen header of function iesys_update_session_flags
  • Fixed issue where nonceTPM was included twice in HMAC.
  • Fixed issue of unused variable when enabling lower default log levels.
  • Fixed tcti-device: 'partial' may be used uninitialized.
  • Fixed double define in tss2_mu.h.
2.4.6
Compare
Choose a tag to compare

[2.4.6] - 2021-05-17

Changed or Fixed

  • Fixed possible access outside the array in ifapi_calculate_tree.
  • Fixed binding of ESYS_TR_RH_NULL (Fixes #1993)
  • Added initialise 'out' parameter in ifapi_json_IFAPI_CONFIG_deserialize.
  • Fixed cleanup in several error cases.
  • Fixed initialization of default log_dir.
  • Fixed error cleanup for key loading and policy execution.
  • Fixed state handling in policy execution.
  • Fixed determination of object type from path.
  • Fixed unused variable warnings when maxloglevel was set to lower default.
  • Fixed issue where nonceTPM was include twice in HMAC calculation.
3.0.3
Compare
Choose a tag to compare

[3.0.3] - 2020-11-25

Changed or Fixed

  • Fix Regression in Fapi_List
  • Fix memory leak in policy calculation
2.4.5
Compare
Choose a tag to compare

[2.4.5] - 2020-11-25

Changed or Fixed

  • Fix Regression in Fapi_List
  • Fix memory leak in policy calculation
3.0.2
Compare
Choose a tag to compare

[3.0.2] - 2020-11-20

Changed or Fixed

  • FAPI: Fix setting of the system flag of NV objects
    This will let NV object metadata be created system-wide always instead of
    locally in the user. Existing metadata will remain in the user directory.
    It can be moved to the corresponding systemstore manually if needed.
  • FAPI: Fix policy searching, when a policyRef was provided
  • FAPI: Accept EK-Certs without CRL dist point
  • FAPI: Fix return codes of Fapi_List
  • FAPI: Fix memleak in policy execution
  • FAPI: Fix coverity NULL-pointer check
  • FAPI: Set the written flag of NV objects in FAPI PolicyNV commands
  • FAPI: Fix deleting of policy files.
  • FAPI: Fix wrong file loading during object search.
  • Fapi: Fix memory leak
  • Fapi: Fix potential NULL-Dereference
  • Fapi: Remove superfluous NULL check
  • Fix a memory leak in async keystore load.
2.4.4
Compare
Choose a tag to compare

[2.4.4] - 2020-11-20

Changed or Fixed

  • FAPI: Fix policy searching, when a policyRef was provided
  • FAPI: Accept EK-Certs without CRL dist point
  • FAPI: Fix memleak in policy execution
  • FAPI: Fix setting of the system flag of NV objects
    This will let NV object metadata be created system-wide always instead of
    locally in the user. Existing metadata will remain in the user directory.
    It can be moved to the corresponding systemstore manually if needed.
  • FAPI: Set the written flag of NV objects in FAPI PolicyNV commands
  • FAPI: Fix deleting of policy files.
  • FAPI: Fix wrong file loading during object search.
  • Fapi: Fix memory leak
  • Fapi: Fix potential NULL-Dereference
  • Fapi: Remove superfluous NULL check
3.0.1
Compare
Choose a tag to compare

Changed or Fixed

  • Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly
    Note that all TPM object created with a PolicyPCR with the currentPcrs
    and currentPcrsAndBank options have been created with an incorrect policy
    that ommits PCR checks. All these objects have to be recreated!
  • Fix bug in FAPI NV creation with custom index values
  • Cleanup of leftover sessions in error cases in FAPI
  • Better error messages in several FAPI errors
  • Add checks to FAPI policy paths
  • Add checks if FAPI is correctly provisioned
  • Fix execution of FAPI policies in some cases
  • Allow 0x prefixes for TPMU_HA in JSON encoding
2.4.3
Compare
Choose a tag to compare

Changed or Fixed

  • Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly
    Note that all TPM object created with a PolicyPCR with the currentPcrs
    and currentPcrsAndBank options have been created with an incorrect policy
    that ommits PCR checks. All these objects have to be recreated!
  • Fix bug in FAPI NV creation with custom index values
  • Cleanup of leftover sessions in error cases in FAPI
  • Better error messages in several FAPI errors
  • Add checks to FAPI policy paths
  • Add checks if FAPI is correctly provisioned
  • Fix execution of FAPI policies in some cases
  • Allow 0x prefixes for TPMU_HA in JSON encoding
Compare
Choose a tag to compare

Changed or Fixed

  • Added setgid perms and ACL for FAPI keystore to allow r/w access for tss group
  • Fixed duoble json_object_put call in event log processing.
  • Added TSS root dir to include path in CFLAGS
  • Switch default FAPI profile to ECC.
  • Enabled all PCR registers for SHA256 bank in the distribution profiles.
  • Added fix computation of PCR logs and PCR digest of PCR logs.
  • Added fix size check for Fapi_Encrypt.
  • Improved log messages in FAPI
  • Introduced new FAPI return codes FAPI_RC_ALREADY_PROVISIONED,
    TSS2_BASE_RC_NOT_PROVISIONED, and TSS2_FAPI_RC_NOT_PROVISIONED.
  • Added missing retry in Fapi_Initialize_Finish.
  • Added man pages for FAPI config files
  • Deleted invalid keys from the null hierarchy.
  • Fixed check of auth state for lockout set.
  • Fixed check of directory access rights in Fapi_Initialize.
  • Enabled usage of NULL hierarchy in FAPI.
  • Added address sanitizer to CI for gcc.
  • Added asserts to callback functions in integration tests
  • Added check event log file before Fapi_PcrExtend.
  • Fixed hierarchy usage and authentication in Fapi_Provision,
    Fapi_GetCertificate, and Fapi_Delete.
  • Added description for primary keys to profile.
  • Fixed non async call of Esys_ContextSave in Fapi_GetEsysBlobs.
  • Added check for hierarchy needed for EvictControl for deleting objects.
  • Fixed copying the primary during key loading.
  • Added a check that prevents deleting of default directories.
  • Added verification to provisioning.
  • Fixed usage of persistent handles.
  • Added missing selectors for some TPMU types in marshal
  • Added handling for invalid selector when (um)marshal TPMU types
  • Improved presentation of Fapi_GetInfo.
  • Fixed computation of the size of a PCR selection.
  • Added a check for valid pathnames in keystore module.
  • Added a check for deleting of the SRK.
  • Fixed computation of random value for objects used for sealing.
  • Fixed return code for event parsing errors.
  • Added content of the config file to FAPI Info.
  • Fixed NV index and path handling in NV creation.
  • Fixed path checking for keys.
  • Fixed version retrieval method in Fapi_GetInfo.
  • Fixed path usage in Fapi_Import.
  • Fixed settings of default flags for keys creation.
  • Fixed handle usage in Fapi_ChangeAuth
  • Fixed systemd-sysusers/-tmpfiles invocation
  • Changed FAPI callback API.
  • Fixed initialization of app data in Esys_Initialize
  • Fixed certificate handling for TPMs without stored certificate.
  • Replaced strtok with strtok_r
  • Changed return codes from tcti macros according to the spec
  • Added check that prevents overwriting objects in key store.
  • Added session usage to FAPI provisioning.
  • Enabled CI for FreeBSD
  • Changed hierarchy param type of Esys_Hash(), Esys_HierarchyControl(),
    Esys_LoadExternal(), and Esys_SequenceComplete() calls along with
    their Async versions according to the spec.
    The can accept both types TPM2_RH and ESYS_TRs as then don't collide.
  • Changed Tss2_Sys_ReadClock to allow audit session to be consistent
    with the rev 1.38 version of the TPM2.0 architecture spec.
    Note: This change brakes ABI backwards compatibility.
  • Silenced expected errors from Esys_TestParams.
  • Many improvements for CI builds on Travis and Cirrus, unit tests
    and integration test code

Added

  • Added SWTPM-TCTI
  • Added mbedTLS ESYS crypto backend
  • Added the Command TCTI
  • Added new API function Fapi_GetEsysBlobs.
  • Added new feature for importing keys with Fapi_Import.

Removed

  • Removed libgcrypt ESYS crypto backend
  • Removed dev-tcti partial read mode configuration flag
  • Removed dev-tcti async mode configuration flag
  • Removed obsolete LIBDL_LDFLAGS and replaced broken @LIBDL_LDFLAGS@ with @LIBADD_DL@
  • Removed deprecated OpenSSL functions from FAPI and ESYS