!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

189 Members
44 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.orgbut I'm thinking about how the bios can wipe it too13:24:08
@andi:kack.itandi-That would mean that I must lock the tpm device away and only let root / a special user interact with it.13:24:25
@andi:kack.itandi-I read some text that said that there are some hardware keys to adjust it13:24:38
@grahamc:nixos.org@grahamc:nixos.orgyou sort of need to do that anyway13:25:12
@grahamc:nixos.org@grahamc:nixos.orgbecause the nvram isn't partitioned or anything, it has no fs, you just have offsets in to the memory you write to13:25:35
@andi:kack.itandi-So you need to coordinate offsets across all your tools? e.g. OpenConnect and my kerberos daemon must each know where they can write?13:26:50
@grahamc:nixos.org@grahamc:nixos.orgmostly tools dont' need to write to the nvram I think13:27:15
@grahamc:nixos.org@grahamc:nixos.orglike, I think the nvram is for "I don't have a filesystem yet!" stuff, plus perhaps password attempt counters13:27:35

Show newer messages


Back to Room ListRoom Version: 6