|
TSS2_RC | Esys_Sign_Async (ESYS_CONTEXT *esysContext, ESYS_TR keyHandle, ESYS_TR shandle1, ESYS_TR shandle2, ESYS_TR shandle3, const TPM2B_DIGEST *digest, const TPMT_SIG_SCHEME *inScheme, const TPMT_TK_HASHCHECK *validation) |
|
TSS2_RC | Esys_Sign (ESYS_CONTEXT *esysContext, ESYS_TR keyHandle, ESYS_TR shandle1, ESYS_TR shandle2, ESYS_TR shandle3, const TPM2B_DIGEST *digest, const TPMT_SIG_SCHEME *inScheme, const TPMT_TK_HASHCHECK *validation, TPMT_SIGNATURE **signature) |
|
TSS2_RC | Esys_Sign_Finish (ESYS_CONTEXT *esysContext, TPMT_SIGNATURE **signature) |
|
ESAPI function to invoke the TPM2_Sign command either as a one-call or in an asynchronous manner.
◆ Esys_Sign()
TSS2_RC Esys_Sign |
( |
ESYS_CONTEXT * |
esysContext, |
|
|
ESYS_TR |
keyHandle, |
|
|
ESYS_TR |
shandle1, |
|
|
ESYS_TR |
shandle2, |
|
|
ESYS_TR |
shandle3, |
|
|
const TPM2B_DIGEST * |
digest, |
|
|
const TPMT_SIG_SCHEME * |
inScheme, |
|
|
const TPMT_TK_HASHCHECK * |
validation, |
|
|
TPMT_SIGNATURE ** |
signature |
|
) |
| |
One-Call function for TPM2_Sign
This function invokes the TPM2_Sign command in a one-call variant. This means the function will block until the TPM response is available. All input parameters are const. The memory for non-simple output parameters is allocated by the function implementation.
- Parameters
-
[in,out] | esysContext | The ESYS_CONTEXT. |
[in] | keyHandle | Handle of key that will perform signing. |
[in] | shandle1 | Session handle for authorization of keyHandle |
[in] | shandle2 | Second session handle. |
[in] | shandle3 | Third session handle. |
[in] | digest | Digest to be signed. |
[in] | inScheme | TPM2_Signing scheme to use if the scheme for keyHandle is TPM2_ALG_NULL. |
[in] | validation | Proof that digest was created by the TPM. |
[out] | signature | The signature. (callee-allocated) |
- Return values
-
TSS2_RC_SUCCESS | if the function call was a success. |
TSS2_ESYS_RC_BAD_REFERENCE | if the esysContext or required input pointers or required output handle references are NULL. |
TSS2_ESYS_RC_BAD_CONTEXT | if esysContext corruption is detected. |
TSS2_ESYS_RC_MEMORY | if the ESAPI cannot allocate enough memory for internal operations or return parameters. |
TSS2_ESYS_RC_BAD_SEQUENCE | if the context has an asynchronous operation already pending. |
TSS2_ESYS_RC_INSUFFICIENT_RESPONSE | if the TPM's response does not at least contain the tag, response length, and response code. |
TSS2_ESYS_RC_MALFORMED_RESPONSE | if the TPM's response is corrupted. |
TSS2_ESYS_RC_RSP_AUTH_FAILED | if the response HMAC from the TPM did not verify. |
TSS2_ESYS_RC_MULTIPLE_DECRYPT_SESSIONS | if more than one session has the 'decrypt' attribute bit set. |
TSS2_ESYS_RC_MULTIPLE_ENCRYPT_SESSIONS | if more than one session has the 'encrypt' attribute bit set. |
TSS2_ESYS_RC_BAD_TR | if any of the ESYS_TR objects are unknown to the ESYS_CONTEXT or are of the wrong type or if required ESYS_TR objects are ESYS_TR_NONE. |
TSS2_ESYS_RC_NO_ENCRYPT_PARAM | if one of the sessions has the 'encrypt' attribute set and the command does not support encryption of the first response parameter. |
TSS2_RCs | produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally. |
◆ Esys_Sign_Async()
TSS2_RC Esys_Sign_Async |
( |
ESYS_CONTEXT * |
esysContext, |
|
|
ESYS_TR |
keyHandle, |
|
|
ESYS_TR |
shandle1, |
|
|
ESYS_TR |
shandle2, |
|
|
ESYS_TR |
shandle3, |
|
|
const TPM2B_DIGEST * |
digest, |
|
|
const TPMT_SIG_SCHEME * |
inScheme, |
|
|
const TPMT_TK_HASHCHECK * |
validation |
|
) |
| |
Asynchronous function for TPM2_Sign
This function invokes the TPM2_Sign command in a asynchronous variant. This means the function will return as soon as the command has been sent downwards the stack to the TPM. All input parameters are const. In order to retrieve the TPM's response call Esys_Sign_Finish.
- Parameters
-
[in,out] | esysContext | The ESYS_CONTEXT. |
[in] | keyHandle | Handle of key that will perform signing. |
[in] | shandle1 | Session handle for authorization of keyHandle |
[in] | shandle2 | Second session handle. |
[in] | shandle3 | Third session handle. |
[in] | digest | Digest to be signed. |
[in] | inScheme | TPM2_Signing scheme to use if the scheme for keyHandle is TPM2_ALG_NULL. |
[in] | validation | Proof that digest was created by the TPM. |
- Return values
-
ESYS_RC_SUCCESS | if the function call was a success. |
TSS2_ESYS_RC_BAD_REFERENCE | if the esysContext or required input pointers or required output handle references are NULL. |
TSS2_ESYS_RC_BAD_CONTEXT | if esysContext corruption is detected. |
TSS2_ESYS_RC_MEMORY | if the ESAPI cannot allocate enough memory for internal operations or return parameters. |
TSS2_RCs | produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally. |
TSS2_ESYS_RC_MULTIPLE_DECRYPT_SESSIONS | if more than one session has the 'decrypt' attribute bit set. |
TSS2_ESYS_RC_MULTIPLE_ENCRYPT_SESSIONS | if more than one session has the 'encrypt' attribute bit set. |
TSS2_ESYS_RC_BAD_TR | if any of the ESYS_TR objects are unknown to the ESYS_CONTEXT or are of the wrong type or if required ESYS_TR objects are ESYS_TR_NONE. |
TSS2_ESYS_RC_NO_ENCRYPT_PARAM | if one of the sessions has the 'encrypt' attribute set and the command does not support encryption of the first response parameter. |
◆ Esys_Sign_Finish()
TSS2_RC Esys_Sign_Finish |
( |
ESYS_CONTEXT * |
esysContext, |
|
|
TPMT_SIGNATURE ** |
signature |
|
) |
| |
Asynchronous finish function for TPM2_Sign
This function returns the results of a TPM2_Sign command invoked via Esys_Sign_Finish. All non-simple output parameters are allocated by the function's implementation. NULL can be passed for every output parameter if the value is not required.
- Parameters
-
[in,out] | esysContext | The ESYS_CONTEXT. |
[out] | signature | The signature. (callee-allocated) |
- Return values
-
TSS2_RC_SUCCESS | on success |
ESYS_RC_SUCCESS | if the function call was a success. |
TSS2_ESYS_RC_BAD_REFERENCE | if the esysContext or required input pointers or required output handle references are NULL. |
TSS2_ESYS_RC_BAD_CONTEXT | if esysContext corruption is detected. |
TSS2_ESYS_RC_MEMORY | if the ESAPI cannot allocate enough memory for internal operations or return parameters. |
TSS2_ESYS_RC_BAD_SEQUENCE | if the context has an asynchronous operation already pending. |
TSS2_ESYS_RC_TRY_AGAIN | if the timeout counter expires before the TPM response is received. |
TSS2_ESYS_RC_INSUFFICIENT_RESPONSE | if the TPM's response does not at least contain the tag, response length, and response code. |
TSS2_ESYS_RC_RSP_AUTH_FAILED | if the response HMAC from the TPM did not verify. |
TSS2_ESYS_RC_MALFORMED_RESPONSE | if the TPM's response is corrupted. |
TSS2_RCs | produced by lower layers of the software stack may be returned to the caller unaltered unless handled internally. |