!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

184 Members
49 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
28 Apr 2023
@elvishjerricco:matrix.orgElvishJerriccoYea the reason to bind things against the section contents of a UKI would be as a poor man's secure boot13:22:58
@elvishjerricco:matrix.orgElvishJerriccoso if you have actual secure boot and bind to pcr 7, it's not important13:23:09
@elvishjerricco:matrix.orgElvishJerriccoand at that point pcrphase is only serving the purpose of phase control, so that the TPM only unlocks things during the appropriate boot phase13:23:36
@elvishjerricco:matrix.orgElvishJerriccoSo I guess you still need something like systemd-measure, except if you don't care about measuring UKI sections you could leave those out and just measure the phase path13:27:07
@elvishjerricco:matrix.orgElvishJerriccowhich I don't think is a mode that systemd-measure will do13:27:30
@baloo_:matrix.orgbalooauthenticode PE hash thing is just a matter of filtering out the checksum and the signature section from the hash17:33:19
@baloo_:matrix.orgbalooother than that, it's a plain hash of the file.17:33:34
@baloo_:matrix.orgbaloo( https://github.com/m4b/goblin/pull/362/files )17:34:54

Show newer messages


Back to Room ListRoom Version: 6