![]() |
![]()
| ![]() |
![]()
TCG Software Stack Developer's Reference NAMETspi_TPM_CMKSetRestrictions - set restrictions on use of delegated Certified Migratable Keys SYNOPSIS#include <tss/tspi.h> TSS_RESULT Tspi_TPM_CMKSetRestrictions(TSS_HTPM hTPM, TSS_CMK_DELEGATE CmkDelegate); DESCRIPTIONTspi_TPM_CMKSetRestrictions is used to set restrictions on the delegated use of Certified Migratable Keys (CMKs). Use of this command cannot itself be delegated. PARAMETERShTPMThe hTPM parameter is used to specify the handle of the TPM object. CmkDelegateThe CmkDelegate parameter is a bitmask describing the kinds of CMKs that can be used in a delegated auth session. Each bit represents a type of key. If the bit of a key type is set, then the CMK can be used in a delegated authorization session, otherwise use of that key will result in a TPM_E_INVALID_KEYUSAGE return code from the TPM. The possible values of CmkDelegate are any combination of the following flags logically OR'd together:
RETURN CODESTspi_TPM_CMKSetRestrictions returns TSS_SUCCESS on success, otherwise one of the following values is returned:
CONFORMING TOTspi_TPM_CMKSetRestrictions conforms to the Trusted Computing Group Software Specification version 1.2 Errata A SEE ALSOTspi_TPM_CMKApproveMA(3), Tspi_TPM_CMKCreateTicket(3), Tspi_Key_CMKCreateBlob(3)
|