- Finding the latest firmware releases
- Infineon OPTIGA™ SLB 9665 TPM2.0
- Updating the SLB 9665
- Adjacent notes
I’ve recently started building a 2U rack server, and went to install the 20pin TPM that I had spare. While the unit worked fine, I noticed the firmware was the original/oldest possible firmware version.
Finding the latest firmware releases
The Trusted Computing Group has a list of verified firmware releases for all of the known TPM chips.
For example, my chip is a Infineon, SLB 9665, and that show’s the latest firmware is 5.63
Infineon OPTIGA™ SLB 9665 TPM2.0
I was able to find both 5.62.3126.2 / 5.63.3353.0, but the upgrade path from 5.0.1089.2 is not perfect. As my firmware ends in .2 and the latest upgrade supports `.0` and I have no idea if that’s a problem.
TPM20_5.0.1089.2_to_TPM20_5.62.3126.2.BIN then in theory
Infineon TPM Firmware Update Tools release version is 01.01.2481.00. TPMFactoryUpd in this release is version 01.01.2212.00. IFXTPMUpdate.efi in this release is version 01.01.2212.00. TVicPort.sys in this release is version 4.0.
This file contains what I believe is the (unmodified) Infineon TPM Firmware Update Tools, but I cannot give any guarantee for this. (I’ve added additional firmware to this 7z).
If you have a more recent version of this package, please forward it to me.
Updating the SLB 9665
Part 1: Error 0xE0295507
I tried to patch the TPM unit I had from the oldest firmware to the latest, and kept hitting this
platformAuth is not the Empty Buffer error.
This seems to be because the TPM (even after it’s been cleared) has been accessed by the computer you’ve attached it too, and you seem to have to clear and then flash the TPM chip before the BIOS/Kernel/OS gets’ it’s grubby little fingers into it…
There is a forum post about people disabling the TPM in the BIOS before they can flash, but this didn’t help me using the SuperMicro server motherboard, as it just makes the TPMFactoryUpd tool fail with a missing TPM error.
Untested: I’ve heard Windows has a powershell
Disable-TpmAutoProvisioning to stop windows from activating any TPM it sees. (I have no idea if that works to resolve the issue above).
Part 2: Success
<TO BE CONTINUED>
- https://github.com/iavael/infineon-firmware-updater (Infineon TPM firmware updater for Linux with Google patches / openssl 1.1.0 patches)
- https://www.supermicro.com/wftp/driver/TPM (Seems to contain some outdated firmware and tooling)