Skip site navigation (1)Skip section navigation (2)

FreeBSD Manual Pages

  
 
  

home | help
tpm2_flushcontext(1)	     General Commands Manual	    tpm2_flushcontext(1)

NAME
     tpm2_flushcontext(1)  -  Remove a specified handle, or all contexts associ-
     ated with a transient object, loaded session or saved session from the TPM.

SYNOPSIS
     tpm2_flushcontext [OPTIONS] [ARGUMENT]

DESCRIPTION
     tpm2_flushcontext(1) - Remove a specified handle, or all  contexts  associ-
     ated with a transient object, loaded session or saved session from the TPM.
     The object to be flushed is specified as the first argument to the tool and
     is  in one of the following forms: - The handle of the object to be flushed
     from the TPM.  Must be a valid handle number.  - Flush a session via a ses-
     sion file.  A session file is generated from tpm2_startauthsession(1)'s  -S
     option.

OPTIONS
     * -t, --transient-object:

       Remove all transient objects.

     * -l, --loaded-session:

       Remove all loaded sessions.

     * -s, --saved-session:

       Remove all saved sessions.

     * ARGUMENT  the  command  line  argument specifies the OBJECT to be removed
       from the TPM resident memory.

     * --cphash=FILE

       File path to record the hash of the command parameters.	This is commonly
       termed as cpHash.  NOTE: When this option is selected, The tool will  not
       actually execute the command, it simply returns a cpHash.

COMMON OPTIONS
     This collection of options are common to many programs and provide informa-
     tion that many users may expect.

     * -h,  --help=[man|no-man]:  Display the tools manpage.  By default, it at-
       tempts to invoke the manpager for the tool, however, on failure will out-
       put a short tool summary.  This is the same behavior if the "man"  option
       argument  is  specified, however if explicit "man" is requested, the tool
       will provide errors from man on stderr.	If the "no-man" option if speci-
       fied, or the manpager fails, the short options will be output to stdout.

       To successfully use the manpages feature requires the manpages to be  in-
       stalled or on MANPATH, See man(1) for more details.

     * -v, --version: Display version information for this tool, supported tctis
       and exit.

     * -V,  --verbose: Increase the information that the tool prints to the con-
       sole during its execution.  When using this option the file and line num-
       ber are printed.

     * -Q, --quiet: Silence normal tool output to stdout.

     * -Z, --enable-errata: Enable the application of errata fixups.  Useful  if
       an  errata fixup needs to be applied to commands sent to the TPM.  Defin-
       ing the environment TPM2TOOLS_ENABLE_ERRATA is equivalent.

TCTI Configuration
     The TCTI or "Transmission Interface" is the  communication  mechanism  with
     the TPM.  TCTIs can be changed for communication with TPMs across different
     mediums.

     To control the TCTI, the tools respect:

     1. The command line option -T or --tcti

     2. The environment variable: TPM2TOOLS_TCTI.

     Note: The command line option always overrides the environment variable.

     The current known TCTIs are:

     * tabrmd	   -	  The	   resource	 manager,      called	  tabrmd
       (https://github.com/tpm2-software/tpm2-abrmd).	Note  that  tabrmd   and
       abrmd as a tcti name are synonymous.

     * mssim - Typically used for communicating to the TPM software simulator.

     * device - Used when talking directly to a TPM device file.

     * none  - Do not initalize a connection with the TPM.  Some tools allow for
       off-tpm options and thus support not using a TCTI.   Tools  that  do  not
       support	it  will  error when attempted to be used without a TCTI connec-
       tion.  Does not support ANY options and MUST BE presented  as  the  exact
       text of "none".

     The arguments to either the command line option or the environment variable
     are in the form:

     <tcti-name>:<tcti-option-config>

     Specifying  an empty string for either the <tcti-name> or <tcti-option-con-
     fig> results in the default being used for that portion respectively.

   TCTI Defaults
     When a TCTI is not specified,  the  default  TCTI	is  searched  for  using
     dlopen(3)	semantics.   The  tools will search for tabrmd, device and mssim
     TCTIs IN THAT ORDER and USE THE FIRST ONE FOUND.  You can query  what  TCTI
     will  be  chosen as the default by using the -v option to print the version
     information.  The "default-tcti" key-value pair will indicate which of  the
     aforementioned TCTIs is the default.

   Custom TCTIs
     Any  TCTI	that  implements  the dynamic TCTI interface can be loaded.  The
     tools internally use dlopen(3), and the raw tcti-name value is used for the
     lookup.  Thus, this could be a path to the shared	library,  or  a  library
     name as understood by dlopen(3) semantics.

TCTI OPTIONS
     This  collection  of  options  are used to configure the various known TCTI
     modules available:

     * device: For the device TCTI, the TPM character device file for use by the
       device TCTI can be specified.  The default is /dev/tpm0.

       Example: -T device:/dev/tpm0 or export TPM2TOOLS_TCTI="device:/dev/tpm0"

     * mssim: For the mssim TCTI, the domain name or IP address and port  number
       used  by  the  simulator can be specified.  The default are 127.0.0.1 and
       2321.

       Example:      -T      mssim:host=localhost,port=2321	 or	  export
       TPM2TOOLS_TCTI="mssim:host=localhost,port=2321"

     * abrmd: For the abrmd TCTI, the configuration string format is a series of
       simple  key value pairs separated by a `,' character.  Each key and value
       string are separated by a `=' character.

       * TCTI abrmd supports two keys:

	 1. `bus_name' : The name of the tabrmd service on the bus (a string).

	 2. `bus_type' : The type of the dbus instance	(a  string)  limited  to
	    `session' and `system'.

       Specify	the  tabrmd  tcti name and a config string of bus_name=com.exam-
       ple.FooBar:

	      \--tcti=tabrmd:bus_name=com.example.FooBar

       Specify the default (abrmd) tcti and a config string of bus_type=session:

	      \--tcti:bus_type=session

       NOTE: abrmd and tabrmd are synonymous.

EXAMPLES
   Flushing a Transient Object
     Typically, when using the TPM, the interactions occur  through  a	resource
     manager, like tpm2-abrmd(8).  When the process exits, transient object han-
     dles  are	flushed.   Thus,  flushing transient objects through the command
     line is not required.  However, when interacting  with  the  TPM  directly,
     this scenario is possible.  The below example assumes direct TPM access not
     brokered by a resource manager.  Specifically we will use the simulator.

	    tpm2_createprimary -Tmssim -c primary.ctx

	    tpm2_getcap -T mssim handles-transient
	    - 0x80000000

	    tpm2_flushcontext -T mssim 0x80000000

   Flush All the Transient Objects
	    tpm2_flushcontext \--transient-object

   Flush a Session
	    tpm2_startauthsession -S session.dat

	    tpm2_flushcontext session.dat

Returns
     Tools can return any of the following codes:

     * 0 - Success.

     * 1 - General non-specific error.

     * 2 - Options handling error.

     * 3 - Authentication error.

     * 4 - TCTI related error.

     * 5 - Non supported scheme.  Applicable to tpm2_testparams.

BUGS
     Github Issues (https://github.com/tpm2-software/tpm2-tools/issues)

HELP
     See     the     Mailing	List	(https://lists.linuxfoundation.org/mail-
     man/listinfo/tpm2)

tpm2-tools						    tpm2_flushcontext(1)

Want to link to this manual page? Use this URL:
<https://man.freebsd.org/cgi/man.cgi?query=tpm2_flushcontext&sektion=1&manpath=FreeBSD+Ports+15.1.quarterly>

home | help