Comment 4 for bug 1940079

Revision history for this message
Paride Legovini (paride) wrote : Re: Strongswan in Focal doesn't support TPM 2.0 through the TSS2 interface...

Thanks Tobias for the additional information. I think that enabling TSS2 in Ubuntu is something we want to do, however I there are a few things to consider:

1. The stable Ubuntu releases are "feature frozen", which means that it is unlikely TSS2 will be enabled in Focal (exceptions are possible, but a very compelling reason is needed). However you mentioned that the strongswan Focal configuration *elides* --enable-tss-tss2. Looking at the packaging file I don't think we're disabling or removing that flag from anywhere. Did TSS2 work before with Ubuntu's strongswan package? (I doubt so, as additional build-deps are needed, admittedly I'm not very familiar with the package.)

2. TSS2 doesn't look enabled in the current Ubuntu development release (Impish). That would normally be the right place to enable a new feature, however the devel release is already in feature freeze. This means that target for enabling TSS2 would be the Ubuntu 22.04 release (modulo [1]).

3. Ideally this change should land in Debian, which as far as I can tell is also missing support for TSS2. Ubuntu would then inherit the change with the next syncs/merges. Debian is out of the freeze, so this is a good moment for proposing the change. Should the change not land in Debian in time for 22.04 we can enable TSS2 in Ubuntu.

What do you think of this plan?

[1] https://wiki.ubuntu.com/FreezeExceptionProcess