Support TPM Key Attestation during certificate generation

Posted: 10/16/2015 07:40:03
by VoxPopuli Robot  (Team)

Key Attestation is a Trusted Platform Module feature that enables the TPM to confirm that the private key is stored within it and is not usable outside the TPM. This is used to ensure that there is only one PC that holds a private key (ensures a unique identity).

It would be great if SecureBlackbox supported certificate request generation that generated the key using the TPM and invoked the Key Attestation feature to attest this in the certificate signing request.

Here is a potentially useful link showcasing some other TPM features that developers are interested in using but that existing security software implementations fail to provide: https://stackoverflow.com/questions/28...ng-the-tpm

Maybe good opportunity for SecureBlackbox to provide some exclusive features here.

