Cannot switch from default to test PCA without manual enrollment or clearing the TPM owner |
|
Issue descriptionWe ask people to use the --attestation-server=test for debugging attestation issues. However, if you use this flag on a device already enrolled against the default PCA, it will not also enroll against the test PCA. This is because TpmIsAttestationPrepared() will return true if the device is enrolled with any PCA. Therefore we don't try to prepare and enroll with the test PCA, and therefore fail. We need a way to be able to enroll from the client if attestation isn't prepared for the given PCA. |
|
►
Sign in to add a comment |
|