1 /* Microsoft Reference Implementation for TPM 2.0
2 *
3 * The copyright in this software is being made available under the BSD License,
4 * included below. This software may be subject to other third party and
5 * contributor rights, including patent rights, and no such rights are granted
6 * under this license.
7 *
8 * Copyright (c) Microsoft Corporation
9 *
10 * All rights reserved.
11 *
12 * BSD License
13 *
14 * Redistribution and use in source and binary forms, with or without modification,
15 * are permitted provided that the following conditions are met:
16 *
17 * Redistributions of source code must retain the above copyright notice, this list
18 * of conditions and the following disclaimer.
19 *
20 * Redistributions in binary form must reproduce the above copyright notice, this
21 * list of conditions and the following disclaimer in the documentation and/or
22 * other materials provided with the distribution.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ""AS IS""
25 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
27 * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
28 * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
29 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
30 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
31 * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
32 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
33 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34 */
35 #include "Tpm.h"
36 #include "SetPrimaryPolicy_fp.h"
37
38 #if CC_SetPrimaryPolicy // Conditional expansion of this file
39
40 /*(See part 3 specification)
41 // Set a hierarchy policy
42 */
43 // Return Type: TPM_RC
44 // TPM_RC_SIZE size of input authPolicy is not consistent with
45 // input hash algorithm
46 TPM_RC
TPM2_SetPrimaryPolicy(SetPrimaryPolicy_In * in)47 TPM2_SetPrimaryPolicy(
48 SetPrimaryPolicy_In *in // IN: input parameter list
49 )
50 {
51 // Input Validation
52
53 // Check the authPolicy consistent with hash algorithm. If the policy size is
54 // zero, then the algorithm is required to be TPM_ALG_NULL
55 if(in->authPolicy.t.size != CryptHashGetDigestSize(in->hashAlg))
56 return TPM_RCS_SIZE + RC_SetPrimaryPolicy_authPolicy;
57
58 // The command need NV update for OWNER and ENDORSEMENT hierarchy, and
59 // might need orderlyState update for PLATFROM hierarchy.
60 // Check if NV is available. A TPM_RC_NV_UNAVAILABLE or TPM_RC_NV_RATE
61 // error may be returned at this point
62 RETURN_IF_NV_IS_NOT_AVAILABLE;
63
64 // Internal Data Update
65
66 // Set hierarchy policy
67 switch(in->authHandle)
68 {
69 case TPM_RH_OWNER:
70 gp.ownerAlg = in->hashAlg;
71 gp.ownerPolicy = in->authPolicy;
72 NV_SYNC_PERSISTENT(ownerAlg);
73 NV_SYNC_PERSISTENT(ownerPolicy);
74 break;
75 case TPM_RH_ENDORSEMENT:
76 gp.endorsementAlg = in->hashAlg;
77 gp.endorsementPolicy = in->authPolicy;
78 NV_SYNC_PERSISTENT(endorsementAlg);
79 NV_SYNC_PERSISTENT(endorsementPolicy);
80 break;
81 case TPM_RH_PLATFORM:
82 gc.platformAlg = in->hashAlg;
83 gc.platformPolicy = in->authPolicy;
84 // need to update orderly state
85 g_clearOrderly = TRUE;
86 break;
87 case TPM_RH_LOCKOUT:
88 gp.lockoutAlg = in->hashAlg;
89 gp.lockoutPolicy = in->authPolicy;
90 NV_SYNC_PERSISTENT(lockoutAlg);
91 NV_SYNC_PERSISTENT(lockoutPolicy);
92 break;
93
94 #define SET_ACT_POLICY(N) \
95 case TPM_RH_ACT_##N: \
96 go.ACT_##N.hashAlg = in->hashAlg; \
97 go.ACT_##N.authPolicy = in->authPolicy; \
98 g_clearOrderly = TRUE; \
99 break;
100
101 FOR_EACH_ACT(SET_ACT_POLICY)
102
103 default:
104 FAIL(FATAL_ERROR_INTERNAL);
105 break;
106 }
107
108 return TPM_RC_SUCCESS;
109 }
110
111 #endif // CC_SetPrimaryPolicy