tpm_setpresence reports the status of the TPM's flags regarding physical presence. This is the default behavior and also accessible via the --status option. Requesting a report of this status prompts for the owner password. The --assert option changes the TPM to the physically present state. The --clear option changes the TPM to the not present state. The --lock option locks the TPM to the current physical presence state for the current boot cycle. The --enable-cmd option allows the TPM to accept local commands to toggle physical presence states. The --disable-cmd option prevents the TPM from accepting local commands to toggle physical presence states. The --enable-hw option allows the TPM to accept hardware signals to toggle physical presence states. The --disable-hw option prevents the TPM from accepting hardware signals to toggle physical presence states. The --set-lifetime-lock option locks the Command and Hardware enablement flags in their current state permenantly. This option can never be undone. The system will attempt to use the owner password to display the current states before preceding unless the --yes option is given to answer yes to all questions. All changes are made with the TSC_Physical Presence API.
tpm_version(1) , tpm_setenable(8) , tpm_setactive(8) , tpm_setownable(8) , tcsd(8)