!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

187 Members
50 Servers

Load older messages


SenderMessageTime
1 Jun 2022
@joerg:thalheim.ioMic92Documentation is severe lacking and the error message are not helpful.17:33:58
@grahamc:nixos.org@grahamc:nixos.orgI haven't personally found that to be true, but it may be that I come to it with some important background context17:34:20
@grahamc:nixos.org@grahamc:nixos.org * I haven't personally found that to be true, but it is probable that I come to it with some important background context17:34:30
@joerg:thalheim.ioMic92They ask end-users to deal with Nonces. If you don't have a background in cryptography, this is just care-less17:38:48
@grahamc:nixos.org@grahamc:nixos.orgah, yeah, that has to do with the otherwise insecure method that the deprecated aws-ec2 auth method uses17:39:06
@grahamc:nixos.org@grahamc:nixos.orgthe iam method doesn't need it and is much safer17:39:14
@grahamc:nixos.org@grahamc:nixos.orgI guess the ec2 method isn't deprecated, but the iam approach is recommended in a way that feels like ec2 was deprecated17:41:47
@joerg:thalheim.ioMic92Yeah, than I would need to hard set the aws region in my instances somehow...17:48:44
@joerg:thalheim.ioMic92 * Yeah, than I would need to set the aws region in my instances somehow to use iam...17:49:20
@grahamc:nixos.org@grahamc:nixos.orgwhy's that?17:51:11
@joerg:thalheim.ioMic92 Because I would for each region a different vault role because of the inferred_aws_region option that I need to set for aws_auth_backend_role. 17:58:39
@grahamc:nixos.org@grahamc:nixos.orgah, gotcha17:58:47
@joerg:thalheim.ioMic92 * Because I would need for each region a different vault role because of the inferred_aws_region option that I need to set for aws_auth_backend_role. 17:59:13
2 Jun 2022
@joerg:thalheim.ioMic92Wow systemd-creds is actually quite cool. This could be used to secure ssh host keys in the initrd for remote unlocking: https://man7.org/linux/man-pages//man1/systemd-creds.1.html05:45:24
@joerg:thalheim.ioMic92Using TPM05:45:29
6 Jun 2022
@shimun:shimun.netshimun ⚡️ joined the room.12:00:32
15 Jun 2022
@florian:web3.foundationFlorian | W3F changed their display name from Florian | W3F to Florian | OoO till 20.06..09:20:58
18 Jun 2022
@atharvaamritkar:matrix.orgwiredhikari joined the room.10:04:14
20 Jun 2022
@florian:web3.foundationFlorian | W3F changed their display name from Florian | OoO till 20.06. to Florian | W3F.08:58:53
27 Jun 2022
@Minijackson:matrix.orgMinijackson joined the room.08:11:41
30 Jun 2022
@florian:web3.foundationFlorian | W3F changed their profile picture.13:15:17
4 Jul 2022
@jakobu5:hellothere.atJakob changed their profile picture.15:48:56
10 Jul 2022
@da:esclear.de@da:esclear.de joined the room.19:18:36
22 Jul 2022
@chrisportela:matrix.orgChris Portela joined the room.20:52:14
26 Jul 2022
@tinybronca:sibnsk.net@tinybronca:sibnsk.net changed their display name from tinybronca to tailrec.14:39:36
@tinybronca:sibnsk.net@tinybronca:sibnsk.net changed their display name from tailrec to tinybronca.15:39:05
28 Jul 2022
@joerg:thalheim.ioMic92Because I have been asked now several times. Secure boot is still not a thing, right? Have someone may be published a manual guide though?15:26:45
@raitobezarius:matrix.orgraitobezarius
In reply to @joerg:thalheim.io
Because I have been asked now several times. Secure boot is still not a thing, right? Have someone may be published a manual guide though?
Well, there is the bootspec-secureboot project
16:03:55
@raitobezarius:matrix.orgraitobezariusBut SB with GRUB or systemd-boot is not trivial to achieve now16:04:07
@raitobezarius:matrix.orgraitobezariusI will be working on this in 2-3 days FWIW16:04:23

Show newer messages


Back to Room ListRoom Version: 6