blob: eceff27d5f8862d5a3f9de87d495e107a17a15e9 [file] [log] [blame]
Simon Glass350497c2015-08-22 18:31:19 -06001#
2# TPM subsystem configuration
3#
4
5menu "TPM support"
6
Miquel Raynal294f82a2018-05-15 11:57:05 +02007config TPM_V1
8 bool "TPMv1.x support"
9 depends on TPM
10 default y
11 help
12 Major TPM versions are not compatible at all, choose either
13 one or the other. This option enables TPMv1.x drivers/commands.
14
Miquel Raynal79920d12018-07-19 22:35:09 +020015if TPM_V1
Miquel Raynal294f82a2018-05-15 11:57:05 +020016
Simon Glass86232c82015-03-06 13:19:07 -070017config TPM_TIS_SANDBOX
18 bool "Enable sandbox TPM driver"
Miquel Raynal294f82a2018-05-15 11:57:05 +020019 depends on TPM_V1 && SANDBOX
Miquel Raynalf965caa2018-07-19 22:35:07 +020020 default y
Simon Glass86232c82015-03-06 13:19:07 -070021 help
Miquel Raynalcf4bfea2018-05-15 11:57:25 +020022 This driver emulates a TPMv1.x, providing access to base functions
Simon Glass86232c82015-03-06 13:19:07 -070023 such as reading and writing TPM private data. This is enough to
24 support Chrome OS verified boot. Extend functionality is not
25 implemented.
Simon Glass350497c2015-08-22 18:31:19 -060026
27config TPM_ATMEL_TWI
28 bool "Enable Atmel TWI TPM device driver"
Miquel Raynal294f82a2018-05-15 11:57:05 +020029 depends on TPM_V1
Simon Glass350497c2015-08-22 18:31:19 -060030 help
31 This driver supports an Atmel TPM device connected on the I2C bus.
32 The usual tpm operations and the 'tpm' command can be used to talk
33 to the device using the standard TPM Interface Specification (TIS)
34 protocol
35
Christophe Ricard8759ff82015-10-06 22:54:41 +020036config TPM_TIS_INFINEON
Simon Glass350497c2015-08-22 18:31:19 -060037 bool "Enable support for Infineon SLB9635/45 TPMs on I2C"
Miquel Raynal294f82a2018-05-15 11:57:05 +020038 depends on TPM_V1 && DM_I2C
Simon Glass350497c2015-08-22 18:31:19 -060039 help
40 This driver supports Infineon TPM devices connected on the I2C bus.
41 The usual tpm operations and the 'tpm' command can be used to talk
42 to the device using the standard TPM Interface Specification (TIS)
43 protocol
44
45config TPM_TIS_I2C_BURST_LIMITATION
46 bool "Enable I2C burst length limitation"
Miquel Raynal4c6759e2018-05-15 11:57:06 +020047 depends on TPM_TIS_INFINEON
Simon Glass350497c2015-08-22 18:31:19 -060048 help
49 Some broken TPMs have a limitation on the number of bytes they can
50 receive in one message. Enable this option to allow you to set this
51 option. The can allow a broken TPM to be used by splitting messages
52 into separate pieces.
53
54config TPM_TIS_I2C_BURST_LIMITATION_LEN
55 int "Length"
56 depends on TPM_TIS_I2C_BURST_LIMITATION
57 help
58 Use this to set the burst limitation length
59
60config TPM_TIS_LPC
61 bool "Enable support for Infineon SLB9635/45 TPMs on LPC"
Miquel Raynal294f82a2018-05-15 11:57:05 +020062 depends on TPM_V1 && X86
Simon Glass350497c2015-08-22 18:31:19 -060063 help
Christophe Ricard628f1d02016-01-21 23:19:14 +010064 This driver supports Infineon TPM devices connected on the LPC bus.
Simon Glass350497c2015-08-22 18:31:19 -060065 The usual tpm operations and the 'tpm' command can be used to talk
66 to the device using the standard TPM Interface Specification (TIS)
67 protocol
68
69config TPM_AUTH_SESSIONS
70 bool "Enable TPM authentication session support"
Miquel Raynal294f82a2018-05-15 11:57:05 +020071 depends on TPM_V1
Simon Glass350497c2015-08-22 18:31:19 -060072 help
73 Enable support for authorised (AUTH1) commands as specified in the
74 TCG Main Specification 1.2. OIAP-authorised versions of the commands
75 TPM_LoadKey2 and TPM_GetPubKey are provided. Both features are
76 available using the 'tpm' command, too.
77
Christophe Ricard88249232016-01-21 23:27:13 +010078config TPM_ST33ZP24_I2C
79 bool "STMicroelectronics ST33ZP24 I2C TPM"
Miquel Raynal294f82a2018-05-15 11:57:05 +020080 depends on TPM_V1 && DM_I2C
Christophe Ricard88249232016-01-21 23:27:13 +010081 ---help---
82 This driver supports STMicroelectronics TPM devices connected on the I2C bus.
83 The usual tpm operations and the 'tpm' command can be used to talk
84 to the device using the standard TPM Interface Specification (TIS)
85 protocol
86
Christophe Ricard5ffadc32016-01-21 23:27:14 +010087config TPM_ST33ZP24_SPI
88 bool "STMicroelectronics ST33ZP24 SPI TPM"
Miquel Raynal294f82a2018-05-15 11:57:05 +020089 depends on TPM_V1 && DM_SPI
Christophe Ricard5ffadc32016-01-21 23:27:14 +010090 ---help---
91 This driver supports STMicroelectronics TPM devices connected on the SPI bus.
92 The usual tpm operations and the 'tpm' command can be used to talk
93 to the device using the standard TPM Interface Specification (TIS)
94 protocol
95
Mario Six4eceb6c2017-01-11 16:00:50 +010096config TPM_FLUSH_RESOURCES
97 bool "Enable TPM resource flushing support"
Miquel Raynal294f82a2018-05-15 11:57:05 +020098 depends on TPM_V1
Mario Six4eceb6c2017-01-11 16:00:50 +010099 help
100 Enable support to flush specific resources (e.g. keys) from the TPM.
101 The functionality is available via the 'tpm' command as well.
mario.six@gdsys.cca5a7ea22017-03-20 10:28:28 +0100102
103config TPM_LOAD_KEY_BY_SHA1
104 bool "Enable TPM key loading by SHA1 support"
Miquel Raynal294f82a2018-05-15 11:57:05 +0200105 depends on TPM_V1
mario.six@gdsys.cca5a7ea22017-03-20 10:28:28 +0100106 help
107 Enable support to load keys into the TPM by identifying
108 their parent via the public key's SHA1 hash.
109 The functionality is available via the 'tpm' command as well.
mario.six@gdsys.cca5bfcc52017-03-20 10:28:30 +0100110
111config TPM_LIST_RESOURCES
112 bool "Enable TPM resource listing support"
Miquel Raynal294f82a2018-05-15 11:57:05 +0200113 depends on TPM_V1
mario.six@gdsys.cca5bfcc52017-03-20 10:28:30 +0100114 help
115 Enable support to list specific resources (e.g. keys) within the TPM.
116 The functionality is available via the 'tpm' command as well.
Miquel Raynal294f82a2018-05-15 11:57:05 +0200117
118endif # TPM_V1
119
120config TPM_V2
121 bool "TPMv2.x support"
122 depends on TPM
Miquel Raynald9252c82018-07-19 22:35:11 +0200123 default y
Miquel Raynal294f82a2018-05-15 11:57:05 +0200124 help
125 Major TPM versions are not compatible at all, choose either
126 one or the other. This option enables TPMv2.x drivers/commands.
127
Miquel Raynal79920d12018-07-19 22:35:09 +0200128if TPM_V2
Miquel Raynal294f82a2018-05-15 11:57:05 +0200129
Simon Glass66262ed2020-02-06 09:55:04 -0700130config TPM2_CR50_I2C
131 bool "Enable support for Google cr50 TPM"
132 depends on DM_I2C
133 help
134 Cr50 is an implementation of a TPM on Google's H1 security chip.
135 This uses the same open-source firmware as the Chromium OS EC.
136 While Cr50 has other features, its primary role is as the root of
137 trust for a device, It operates like a TPM and can be used with
138 verified boot. Cr50 is used on recent Chromebooks (since 2017).
139
Simon Glasse7ca7da2022-04-30 00:56:53 -0600140config SPL_TPM2_CR50_I2C
141 bool "Enable support for Google cr50 TPM"
142 depends on DM_I2C && SPL_TPM
143 help
144 Cr50 is an implementation of a TPM on Google's H1 security chip.
145 This uses the same open-source firmware as the Chromium OS EC.
146 While Cr50 has other features, its primary role is as the root of
147 trust for a device, It operates like a TPM and can be used with
148 verified boot. Cr50 is used on recent Chromebooks (since 2017).
149
150config TPL_TPM2_CR50_I2C
151 bool "Enable support for Google cr50 TPM"
152 depends on DM_I2C && TPL_TPM
153 help
154 Cr50 is an implementation of a TPM on Google's H1 security chip.
155 This uses the same open-source firmware as the Chromium OS EC.
156 While Cr50 has other features, its primary role is as the root of
157 trust for a device, It operates like a TPM and can be used with
158 verified boot. Cr50 is used on recent Chromebooks (since 2017).
159
160config VPL_TPM2_CR50_I2C
161 bool "Enable support for Google cr50 TPM"
162 depends on DM_I2C && VPL_TPM
163 help
164 Cr50 is an implementation of a TPM on Google's H1 security chip.
165 This uses the same open-source firmware as the Chromium OS EC.
166 While Cr50 has other features, its primary role is as the root of
167 trust for a device, It operates like a TPM and can be used with
168 verified boot. Cr50 is used on recent Chromebooks (since 2017).
169
Miquel Raynalcf4bfea2018-05-15 11:57:25 +0200170config TPM2_TIS_SANDBOX
171 bool "Enable sandbox TPMv2.x driver"
172 depends on TPM_V2 && SANDBOX
Miquel Raynalf965caa2018-07-19 22:35:07 +0200173 default y
Miquel Raynalcf4bfea2018-05-15 11:57:25 +0200174 help
175 This driver emulates a TPMv2.x, providing access to base functions
176 such as basic configuration, PCR extension and PCR read. Extended
177 functionalities are not implemented.
178
Miquel Raynalc1f6d6c2018-05-15 11:57:21 +0200179config TPM2_TIS_SPI
180 bool "Enable support for TPMv2.x SPI chips"
181 depends on TPM_V2 && DM_SPI
Miquel Raynalc1f6d6c2018-05-15 11:57:21 +0200182 help
183 This driver supports TPMv2.x devices connected on the SPI bus.
184 The usual TPM operations and the 'tpm' command can be used to talk
185 to the device using the standard TPM Interface Specification (TIS)
186 protocol.
187
Thirupathaiah Annapureddy22bc2ff2020-01-12 23:34:22 -0800188config TPM2_FTPM_TEE
189 bool "TEE based fTPM Interface"
190 depends on TEE && OPTEE && TPM_V2
191 help
192 This driver supports firmware TPM running in TEE.
193
Ilias Apalodimase61c48d2021-11-09 09:02:18 +0200194config TPM2_MMIO
195 bool "MMIO based TPM2 Interface"
196 depends on TPM_V2
197 help
198 This driver supports firmware TPM2.0 MMIO interface.
199 The usual TPM operations and the 'tpm' command can be used to talk
200 to the device using the standard TPM Interface Specification (TIS)
201 protocol.
202
Miquel Raynal294f82a2018-05-15 11:57:05 +0200203endif # TPM_V2
204
Simon Glass350497c2015-08-22 18:31:19 -0600205endmenu