!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

188 Members
44 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.orgoh wowo19:00:37
@grahamc:nixos.org@grahamc:nixos.orgnice19:00:54
@andi:kack.itandi-There you go :P19:01:07
@grahamc:nixos.org@grahamc:nixos.orgpage 67 TPM_PT_LOCKOUT_RECOVERY https://trustedcomputinggroup.org/wp-content/uploads/TPM-Rev-2.0-Part-2-Structures-01.38.pdf19:23:51
@grahamc:nixos.org@grahamc:nixos.orgnot pointing anything out there just a primary source for the meaning of these values19:26:30
@grahamc:nixos.org@grahamc:nixos.org removed the room topic "Exploring TPMs on NixOS".19:31:12
@grahamc:nixos.org@grahamc:nixos.org andi-: should I change the main address to be #tpm:nixos.org? 19:37:09
@andi:kack.itandi-Sure19:37:56
@grahamc:nixos.org@grahamc:nixos.orgI'm a little confused, failedTries hasn't decremented despite recoveryTime elapsing several times19:42:47
@grahamc:nixos.org@grahamc:nixos.orgso, seeing this happen I decided to look at the spec19:45:54
@grahamc:nixos.org@grahamc:nixos.org
failedTries(NV) –This counter is incremented when the TPM returns TPM_RC_AUTH_FAIL. TPM2_Clear() will reset this counter to zero. This counter is also set to zero on a successful invocation of TPM2_DictionaryAttackLockReset(). This counter is decremented by one after recoveryTimeseconds if:the TPM does not record an authorization failure of a DA-protected entity,there is no power interruption, andfailedTriesis not zero
19:46:14
@grahamc:nixos.org@grahamc:nixos.orgI think I have errata lol19:47:56
@grahamc:nixos.org@grahamc:nixos.org andi-: do you have a handy tpm simulator's source link? 19:51:04
@andi:kack.itandi-One sec I read that earlier somewhere. If you use libvirt that is supposed to just work but with QEMU you have to launch a daemon..19:51:37
@andi:kack.itandi-https://documentation.suse.com/sles/15-SP3/html/SLES-all/tpm.html19:52:04
@grahamc:nixos.org@grahamc:nixos.orghm19:58:23
@grahamc:nixos.org@grahamc:nixos.organnoying20:01:01

Show newer messages


Back to Room ListRoom Version: 6