On 10/24/2018 3:34 AM, James Bottomley wrote:
so we'd have to derive the RSA EK primary (which can take up to 60 seconds)
Just FYI: The TPM vendors seem to be caching the two standard EKs during manufacturing. When the TPM detects the EK template during createprimary, it quickly returns the cached value. This optimization is not required, but it is common.