swtpm/src
Stefan Berger 71cc7a41e0 swtpm_cert: Enable signing of EK certificates with hashless signing schemes
Enable swtpm_cert to sign EK certificates with ML-DSA and EdDSA keys.

An ML-DSA-87 EK signed by an ML-DSA-87 private key (currently) leads to
an EK certificate of ~7567 bytes. Therefore, large NVRAM spaces are needed
to store such certificates.

Also allow signing of the certificates with EdDSA keys, such as Ed25519 and
Ed448.

Add a recommendation for CA keys to the swtpm_setup man page.

Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
2026-06-03 16:30:44 -04:00
..
selinux selinux: Add SELinux policy for virtqemud_t swtpm_t setsched process and unix socket interactions. 2026-05-28 08:06:25 -04:00
swtpm swtpm: Remove SOCK_CLOEXEC flag from socket call 2026-05-19 11:38:00 -04:00
swtpm_bios swtpm_bios: Rename parameter from optarg to opt_arg (OS X,Wshadow) 2024-10-13 19:46:15 -04:00
swtpm_cert swtpm_cert: Enable signing of EK certificates with hashless signing schemes 2026-06-03 16:30:44 -04:00
swtpm_ioctl all: Apply a delay factor to timeouts for very old architectures 2026-03-05 21:08:00 -05:00
swtpm_localca swtpm_localca: Replace certtool with openssl for creating CAs 2026-05-05 13:41:20 -04:00
swtpm_setup swtpm_setup: Remove casts to arrays since unacceptable to clang 2026-05-19 11:38:00 -04:00
utils swtpm_setup, swtpm_localca: Add compiler attribute for printf to logging functions 2026-04-14 17:41:51 -04:00
Makefile.am swtpm: install sysusers.d and tmpfiles.d configs 2025-09-23 09:32:29 -04:00
swtpm-sysusers.conf.in swtpm: install sysusers.d and tmpfiles.d configs 2025-09-23 09:32:29 -04:00
swtpm-tmpfiles.conf.in swtpm: install sysusers.d and tmpfiles.d configs 2025-09-23 09:32:29 -04:00