swtpm(8) swtpm(8) (NAME) swtpm - TPM . . (SYNOPSIS) swtpm socket [OPTIONS] swtpm chardev [OPTIONS] swtpm cuse [OPTIONS] (DESCRIPTION) swtpm TPM libtpms . TPM TCP/IP (chardev) CUSE ( ) TPM . swtpm TPM_PORT TCP/IP TPM . TPM_PATH TPM . swtpm SIGTERM . cuse swtpm TPM (root) . (Options for socket interface) socket : -p|--port TPM_PORT. -t|--terminate TPM ( TCP). --server [type=tcp][,port=[,bindaddr=
[,ifname=]]][,fd=][,disconnect] TCP fd . ni-shani bind ( ) TCP 127.0.0.1 . IPv6 (link-local) ifname . disconnect . -p --fd . --server type=unixio[,path=][,fd=] [,mode=<0...>][,uid=][,gid=] UnixIO . . mode UnixIO . '0' . 0770 . uid gid UnixIO . (root) . (Options for character device interface) chardev : -c|--chardev TPM . --vtpm-proxy vTPM TPM (backend) . CUSE (Options for the CUSE interface) cuse : -n|--name TPM . /dev . . -M|--maj (major number) . -m|--min (minor number) . (Options for socket and character device interfaces:) : -f|--fd TPM . -t . -d|--daemon (daemonize). --ctrl type=[unixio|tcp][,path=] [,port=[,bindaddr=
[,ifname=]]] [,fd=|clientfd=] [,mode=<0...>][,uid=][,gid=][,terminate] TPM . UnixIO path filedescriptor TCP port filedescriptor . nishani bind ( ) TCP 127.0.0.1 . IPv6 (link-local) ifname . mode UnixIO . '0' . 0770 . uid gid UnixIO . (root) . terminate swtpm . QEMU CMD_SHUTDOWN swtpm . (out-of-band) TPM (reset) . (Options for all interfaces) : --tpmstate dir=|backend-uri=[,mode=<0...>][,lock] TPM_PATH. dir TPM mode dir . '0' . 0640 . backend-uri TPM URI . backend-uri=dir:// backend-uri=file:// . 'dir://' URI . path_to_dir '/' . 'file://' URI TPM . . ( v0.7) lock TPM TPM swtpm . . . . lock=false . --tpm2 TPM 2 TPM 1.2 . --log [fd=|file=][,level=] [,prefix=][,truncate] () . '-' . level . libtpms . prefix . . truncate () . --locality reject-locality-4[,allow-set-locality] reject-locality-4 TPM (locality 4) TPM . allow-set-locality swtpm TPM/TPM2_SetLocality . VTPM . --vtpm-proxy . TPM/TPM2_SetLocality . --key file=|fd= [,format=][,mode=aes-cbc|aes-256-cbc], [remove[=true|false]] TPM. AES ( ) ( ) . . () '0x' . mode . aes-cbc ( aes-128-cbc) aes-256-cbc . encrypt-then-mac . remove . --key pwdfile=|pwdfd= [,mode=aes-cbc|aes-256-cbc][remove[=true|false]][,kdf=sha512|pbkdf2] (passphrase) . SHA512 PBKDF2 . PBKDF2 . --migration-key file=|fd= [,format=][,mode=aes-cbc|aes-256-cbc] [,remove[=true|false]] TPM (blobs) ioctl . TPM --key . TPM . TPM TPM . TPM TPM . TPM TPM TPM . TPM . AES ( ) ( ) . . () '0x' . mode . aes-cbc ( aes-128-cbc) aes-256-cbc . encrypt-then-mac . remove . --migration-key pwdfile=|pwdfd= [,mode=aes-cbc|aes-256-cbc][,remove[=true|false]][,pdf=sha512|pbkdf2] . SHA512 PBKDF2 . PBKDF2 . --pid file=|fd= (PID) TPM . . -r|--runas . swtpm (root) . -R|--chroot (Chroot) . swtpm (root) . --seccomp action=none|log|kill (since v0.2) seccomp . kill . seccomp none . log . log libseccomp . swtpm libseccomp . --flags [not-need-init][,startup-clear|startup-state|startup-deactivated|startup-none][,disable-auto-shutdown] not-need-init TPM TPM INIT ( '-i' swtpm_ioctl ). startup TPM_Startup TPM2_Startup . startup-deactivated TPM 1.2 . not-need-init startup-none . --vtpm-proxy startup-clear . disable-auto-shutdown TPM2_Shutdown() swtpm TPM 2 swtpm . swtpm (DA) TPM 2 TPM2_Shutdown() . --print-capabilities (since v0.2) 0.1 swtpm . : { "type": "swtpm", "features": [ "tpm-1.2", "tpm-2.0", "tpm-send-command-header", "flags-opt-startup", "flags-opt-disable-auto-shutdown", "cmdarg-seccomp", "cmdarg-key-fd", "cmdarg-pwd-fd", "cmdarg-print-states", "cmdarg-chroot", "cmdarg-migration", "nvram-backend-dir", "nvram-backend-file", "rsa-keysize-1024", "rsa-keysize-2048", "rsa-keysize-3072", "cmdarg-profile", "cmdarg-print-profiles", "profile-opt-remove-disabled", "cmdarg-print-info", "tpmstate-opt-lock" ], "version": "0.7.0" } v0.7 . : tpm-1.2 (since v0.7) TPM 1.2 (libtpms 1.2 ). tpm-2.0 (since v0.7) TPM 2 (libtpms 2.0 ). ( --tpm2 ) cmdarg-seccomp (since v0.2) --seccomp . cmdarg-key-fd (since v0.2) --key fd= . cmdarg-pwd-fd (since v0.2) --key pwdfd= . cmdarg-print-states (since v0.7) --print-states . cmdarg-chroot (since v0.8) --chroot . cmdarg-migration (since v0.8) --migration . nvram-backend-dir (since v0.7) --tpmstate backend-uri=dir://... . nvram-backend-file (since v0.7) --tpmstate backend-uri=file://... . tpm-send-command-header (since v0.2) TPM 2 locality TPM 2 . TPM 2 . big endian . flags-opt-startup (since v0.3) --flags startup-... . flags-opt-disable-auto-shutdown (since v0.8) --flags disable-auto-shutdown . rsa-keysize-2048 (since v0.4) TPM 2 RSA . rsa-keysize RSA . cmdarg-profile (since v0.10) --profile () TPM 2 name= profile= fd= file= . cmdarg-print-profiles (since v0.10) --print-profiles . profile-opt-remove-disabled (since v0.10) --profile remove-disabled . cmdard-print-info (since v0.10) --print-info . tpmstate-opt-lock (since v0.10) lock --tpmstate . --print-states (since v0.7) TPM 1.2 TPM 2 . --tpmstate TPM 2 --tpm2 . JSON . 'permall' 'volatile' . { "type": "swtpm", "states": [ { "name": "permall", "size": 6013 }, { "name": "volatile", "size": 1087 } ] } --migration [incoming][,release-lock-outgoing] NVRAM swtpm . . incoming swtpm NVRAM TPM ( ) . release-lock-outgoing swtpm 'savestate' TPM swtpm NVRAM . 'permanent' 'volatile' 'savestate' . --profile name=|profile=|file=|fd=[,remove-disabled=check|fips-host] (since v0.10) (profile) TPM 2 . name= . profile= JSON . file= JSON . fd= . () . 'custom' 'custom:' TPM 2 . 'custom' . 'custom' 'custom:test' 'fips-host' : [...] --profile '{"Name":"custom:test", "Attributes":"fips-host"}' TPM 2 . . remove-disabled swtpm FIPS ( fips-host FIPS RHEL 9.4 ) OpenSSL . check . custom . ( ) : o camellia tdes rsaes ( RSA PKCS#1 v1.5) o (RSA EC) SHA1 o RSA o RSA o EC FIPS ecdaa ecschnorr . FIPS . swtpm (Attributes) StateFormatLevel StateFormatLevel . swtpm : $ swtpm socket --tpmstate dir=./ --tpm2 --print-info 0x08 | jq { "RuntimeAlgorithms": { "Implemented": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,\ hmac,aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,\ sha384,sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,\ ecdh,ecdaa,sm2,ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,\ kdf1-sp800-108,ecc,ecc-min-size=192,ecc-nist,ecc-bn,\ ecc-nist-p192,ecc-nist-p224,ecc-nist-p256,\ ecc-nist-p384,ecc-nist-p521,ecc-bn-p256,ecc-bn-p638,\ ecc-sm2-p256,symcipher,camellia,camellia-min-size=128,\ cmac,ctr,ofb,cbc,cfb,ecb", "CanBeDisabled": "tdes,sha1,sha512,rsassa,rsaes,rsapss,ecmqv,\ ecc-nist-p192,ecc-nist-p224,ecc-nist-p521,\ ecc-bn-p256,ecc-bn-p638,ecc-sm2-p256,camellia,cmac,\ ctr,ofb,cbc,ecb", "Enabled": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,hmac,\ aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,sha384,\ sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,ecdh,ecdaa,sm2,\ ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,kdf1-sp800-108,ecc,\ ecc-min-size=192,ecc-nist,ecc-bn,symcipher,camellia,\ camellia-min-size=128,cmac,ctr,ofb,cbc,cfb,ecb", "Disabled": "" } } : $ swtpm socket --tpmstate dir=./ --tpm2 --print-info 0x10 | jq { "RuntimeCommands": { "Implemented": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197,0x199-0x19c", "CanBeDisabled": "0x11f,0x121-0x122,0x124-0x128,0x12a,0x12c-0x12e,\ 0x130,0x132-0x13b,0x13d-0x140,0x142,0x146-0x147,\ 0x149-0x14d,0x14f-0x152,0x154-0x155,0x159,0x15b,\ 0x15d-0x15e,0x160-0x164,0x167-0x168,0x16a-0x172,\ 0x174,0x177-0x178,0x17b,0x17f-0x181,0x183-0x184,\ 0x187-0x193,0x197,0x199-0x19c", "Enabled": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197,0x199-0x19c", "Disabled": "" } } : $ swtpm socket --tpmstate dir=./ --tpm2 --print-info 0x80 | jq { "RuntimeAttributes": { "Implemented": "no-unpadded-encryption,no-sha1-signing,\ no-sha1-verification,no-sha1-hmac-creation,\ no-sha1-hmac-verification,no-sha1-hmac,fips-host", "CanBeDisabled": "no-unpadded-encryption,no-sha1-signing,\ no-sha1-verification,no-sha1-hmac-creation,\ no-sha1-hmac-verification,no-sha1-hmac,fips-host", "Enabled": "no-unpadded-encryption,no-sha1-signing,\ no-sha1-verification,no-sha1-hmac", "Disabled": "no-sha1-hmac-creation,no-sha1-hmac-verification,fips-host" } } "Attributes" "Algorithms" "Commands" . : $ swtpm socket --tpm2 --print-info 0x40 | jq { "AvailableProfiles": [ { "Name": "default-v1", "StateFormatLevel": 4, "Commands": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197,0x199-0x19a", "Algorithms": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,\ hmac,aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,\ sha384,sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,\ ecdh,ecdaa,sm2,ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,\ kdf1-sp800-108,ecc,ecc-min-size=192,ecc-nist,ecc-bn,\ symcipher,camellia,camellia-min-size=128,cmac,ctr,\ ofb,cbc,cfb,ecb", "Description": "This profile enables all currently supported \ commands and algorithms. It is applied when the \ user chooses no profile." }, { "Name": "null", "StateFormatLevel": 1, "Commands": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197", "Algorithms": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,\ hmac,aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,\ sha384,sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,\ ecdh,ecdaa,sm2,ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,\ kdf1-sp800-108,ecc,ecc-min-size=192,ecc-nist,ecc-bn,\ symcipher,camellia,camellia-min-size=128,cmac,ctr,\ ofb,cbc,cfb,ecb", "Description": "The profile enables the commands and algorithms \ that were enabled in libtpms v0.9. This profile is \ automatically used when the state does not have a \ profile, for example when it was created by \ libtpms v0.9 or before." }, { "Name": "custom", "StateFormatLevel": 2, "Commands": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197", "Algorithms": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,\ hmac,aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,\ sha384,sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,\ ecdh,ecdaa,sm2,ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,\ kdf1-sp800-108,ecc,ecc-min-size=192,ecc-nist,ecc-bn,\ ecc-sm2-p256,symcipher,camellia,\ camellia-min-size=128,cmac,ctr,ofb,cbc,cfb,ecb", "Description": "This profile allows customization of enabled \ algorithms and commands. This profile requires at \ least libtpms v0.10." } ] } swtpm : $ swtpm_ioctl --tcp :2322 --info 0x20 | jq { "ActiveProfile": { "Name": "default-v1", "StateFormatLevel": 4, "Commands": "0x11f-0x122,0x124-0x12e,0x130-0x140,0x142-0x159,\ 0x15b-0x15e,0x160-0x165,0x167-0x174,0x176-0x178,\ 0x17a-0x193,0x197,0x199-0x19a", "Algorithms": "rsa,rsa-min-size=1024,tdes,tdes-min-size=128,sha1,\ hmac,aes,aes-min-size=128,mgf1,keyedhash,xor,sha256,\ sha384,sha512,null,rsassa,rsaes,rsapss,oaep,ecdsa,\ ecdh,ecdaa,sm2,ecschnorr,ecmqv,kdf1-sp800-56a,kdf2,\ kdf1-sp800-108,ecc,ecc-min-size=192,ecc-nist,ecc-bn,\ symcipher,camellia,camellia-min-size=128,cmac,ctr,\ ofb,cbc,cfb,ecb", "Description": "This profile enables all currently supported \ commands and algorithms. It is applied when the \ user chooses no profile." } } 'custom' . . TPM 2 . --print-profiles (since v0.10) libtpms. --tpm2 . --print-info (since v0.10) TPM TPMLIB_GetInfo libtpms . TPM 2 --tpm2 . --tpmstate . TPM . . OR ( ) : o 0x1: TPM o 0x2: TPM o 0x4: RSA Camellia o 0x8: o 0x10: o 0x20: o 0x40: (built-in) o 0x80: -h|--help . (NOTES) TPM 2 TPM2_Shutdown() TPM 2 TPM_PT_LOCKOUT_COUNTER (DA) (TPM2_Startup()) TPM 2 . TPM_PT_LOCKOUT_COUNTER TPM 2 TPM 2 . NVRAM DA swtpm TPM2_Shutdown() . swtpm TPM2_Shutdown(SU_STATE) TPM2_Shutdown(SU_CLEAR) . (SEE ALSO) swtpm_bios, swtpm_cuse swtpm 2026-03-26 swtpm(8)