When authenticating via an HMAC to the TPM for authorization to use a policy, client sends password and message to TPM server to generate HMAC, receives it back and then uses HMAC for authorization to use an object. Upstream patch: https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d69985157
Created tpm2-tools tracking bugs for this issue: Affects: epel-7 [bug 1465342] Affects: fedora-all [bug 1465343]
Acknowledgments: Name: William Roberts (Intel) Upstream: Imran Desai (Intel)