Skip to content

Verify the requester's GIVE_PUB key in the fwTPM responder #22

Description

@aidangarske

Problem

The fwTPM SPDM responder (src/spdm_responder.c) records the requester public key from GIVE_PUB but never verifies the requester: it does not request or check a requester signature in FINISH, so any requester that completes KEY_EXCHANGE gets a session. This is documented in wolfspdm/spdm_responder.h and is the same in wolfTPM master.

Proposal

Have the responder set MutAuthRequested in KEY_EXCHANGE_RSP when a requester key is expected, verify the requester signature in FINISH against the GIVE_PUB key (or a provisioned trusted requester key), and reject FINISH on mismatch. Related to requester-side mutual auth in #14.

Specification references

DSP0274 KEY_EXCHANGE_RSP MutAuthRequested and FINISH RequesterSignature; TCG SPDM binding GIVE_PUB.

Acceptance criteria

  • Unit test: FINISH with a wrong or missing requester signature is rejected when mutual auth is requested.
  • fwTPM TCG e2e (spdm_test.sh fwtpm-tcg) still passes with the correct requester key.

Area

responder, TCG binding

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium: needed but not blocking; bug with a workaroundenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions