!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

182 Members
51 Servers

Load older messages


SenderMessageTime
11 Dec 2021
@hexa:lossy.networkhexaavailable with v25014:04:06
21 Dec 2021
@roosemberth:orbstheorem.chRoos changed their display name from Roos to Roos (vi/nvim).12:26:38
@roosemberth:orbstheorem.chRoos changed their display name from Roos (vi/nvim) to Roos.21:49:15
22 Dec 2021
@bernardo:matrix.parity.iobernardo joined the room.22:27:20
26 Dec 2021
@raitobezarius:matrix.orgraitobezarius joined the room.15:54:06
@bernardo:matrix.parity.iobernardo changed their display name from bernardo to bernardo ooo.20:57:46
28 Dec 2021
@hax404:hax404.dehax404 joined the room.00:50:30
29 Dec 2021
@zhaofeng:zhaofeng.liZhaofeng Li joined the room.03:59:56
30 Dec 2021
@aditsachde:matrix.orgAdit joined the room.07:44:29
31 Dec 2021
@mexisme:matrix.orgmexisme joined the room.23:10:59
2 Jan 2022
@zuckerberg:neet.spacezuckerberg joined the room.04:14:39
11 Jan 2022
@bernardo:matrix.parity.iobernardo changed their display name from bernardo ooo to bernardo.21:22:51
13 Jan 2022
@hougo:matrix.orghougo left the room.08:08:45
14 Jan 2022
@cw:kernelpanic.cafeChinchilla Washington changed their display name from Rev. CornWallace III (novus ordo seclorum) to coilWinder.04:39:44
@cw:kernelpanic.cafeChinchilla Washington changed their display name from coilWinder to CoilWinder (novus ordo seclorum).04:42:07
20 Jan 2022
@andi:kack.itandi- left the room.08:30:57
24 Jan 2022
@colemickens:matrix.orgcolemickensAre general Secure Boot questions okay here?22:31:52
@colemickens:matrix.orgcolemickensI got NixOS booting in Secure Boot mode by using Fedora's shim and disabling validation in the shim. I'm nervous though that another UEFI update will reset NVRAM, I'll lose the disabled validation and be locked out again. Curious if anyone knows for sure.22:32:34
@zhaofeng:zhaofeng.liZhaofeng LiYou can get actual Secure Boot signing working with https://github.com/frogamic/nix-machines/tree/main/modules/systemd-secure-boot22:34:15
@zhaofeng:zhaofeng.liZhaofeng LiDoes your motherboard vendor allow enrolling your own keys?22:34:46
@colemickens:matrix.orgcolemickensI'm pretty sure my laptop doesn't, but now I'm realizing that it well could have the same issue (does user enrolled keys get stored in nvram)22:35:50
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @colemickens:matrix.org
I'm pretty sure my laptop doesn't, but now I'm realizing that it well could have the same issue (does user enrolled keys get stored in nvram)
Both of my laptop (Framework) and custom desktop allow this, and they do survive BIOS upgrades
22:37:37
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @colemickens:matrix.org
I'm pretty sure my laptop doesn't, but now I'm realizing that it well could have the same issue (does user enrolled keys get stored in nvram)
* Both of my laptop (Framework) and custom desktop allow this, and they do survive BIOS upgrades in my case
22:37:44
@zhaofeng:zhaofeng.liZhaofeng Li And it's not just user enrolled keys, you are enrolling the PK and transitioning Secure Boot to User mode 22:38:46
@zhaofeng:zhaofeng.liZhaofeng LiBIOSes usually have an option to use the "default" setup which would enroll the Microsoft PK22:39:21
@colemickens:matrix.orgcolemickensActually, it does have a "Reset to Setup Mode" that will clear the platform key and let me enroll one.22:39:58
@colemickens:matrix.orgcolemickensBut :/ also I dual-boot Windows. idk if one can enroll multiple platform keys22:40:12
@zhaofeng:zhaofeng.liZhaofeng LiYeah, that's what you want to use22:40:16
@zhaofeng:zhaofeng.liZhaofeng LiYou can still dual-boot Windows, just allow Microsoft's certificates in your db22:41:29
@zhaofeng:zhaofeng.liZhaofeng LiFound it: https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#Dual_booting_with_other_operating_systems22:42:16

Show newer messages


Back to Room ListRoom Version: 6