On 3/31/2024 12:52 PM, Gabríel Arthúr Pétursson wrote:
The TPM specifications have a standardized set of templates for the Endorsement Keys, and a recommendation on a template to create/provision the shared SRK.
The original TCG guidance document for an SRK used arrays of zeros for the unique field.
This was either a holdover from TPM 1.2, where arrays were 20 bytes, or a misinterpretation of text that said: NULL. The reality is that it's a TPM2B, and the size(s) can be zero. The answer for the EK is different. It has to use the TCG standard. The EK is not a 'guidance document'.