[Bug 3510] New: OVMF: The TPM 2 platform hierarchy must be disabled



Bug ID: 3510
Summary: OVMF: The TPM 2 platform hierarchy must be disabled
Per the TCG firmware specification "TCG PC Client Platform Firmware Profile
Specification" the TPM 2 platform hierarchy needs to be disabled or a random
password set and discarded before the firmware passes control to the next stage
bootloader or kernel.

Current specs are here:

Section 11 states:
"Platform Firmware MUST protect access to the Platform Hierarchy and prevent
access to the platform hierarchy by non-manufacturer-controlled components. "

Ideally the bugfix would be applied to a recent stable branch as well.

