!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

171 Members
42 Servers

Load older messages


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.orghttps://www.mankier.com/1/tpm2_quote12:21:10
@linus.heckemann:matrix.mayflower.deLinux Hackerman is moving: @linus:schreibt.jetzt joined the room.12:21:36
@andi:kack.itandi-I must also look at the OpenConnect VPN client. Apparently they integrate with the kernel keyring but there are also mentions of the TSS lib somewhere. Perhaps that stuff is really interoperable. At first I didn't think that could be the case.12:22:58
@grahamc:nixos.org@grahamc:nixos.orgI wonder if the openconnect server can require your PCRs to match specific values to allow a connection12:24:00
@voyager:t2bot.ioMatrix Traveler (bot) joined the room.12:24:04
@grahamc:nixos.org@grahamc:nixos.org * I wonder if the openconnect client key can require your PCRs to match specific values to allow a connection12:24:11
@andi:kack.itandi-Off-topic: Do we now have all the bots on the matrix universe? :D12:24:22
@grahamc:nixos.org@grahamc:nixos.orgI would not be surprised if that were true, the TPM2 book talks about it a lot :D12:24:22
@grahamc:nixos.org@grahamc:nixos.orghaha12:24:33
@andi:kack.itandi-It is nice that we have a well documented user of all of the TPM infrastructure.12:41:49
@hexa:lossy.networkhexa joined the room.12:41:58
@andi:kack.itandi-I now wish that I could use the TPM for wireguard key derivation.12:41:58
@grahamc:nixos.org@grahamc:nixos.orgis that openconnect?12:42:04
@andi:kack.itandi-Yeah12:42:10
@grahamc:nixos.org@grahamc:nixos.org:)12:42:14
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels 13:00:04
@andi:kack.itandi- So yesterday I was able to wipe my state without th ecorrect password IIRC. All I did was call tpm2_clear. 13:16:47
@andi:kack.itandi-How do you protect against that?13:17:04
@andi:kack.itandi-IIRC I did set two passwords when I first setup secrets.13:17:24
@grahamc:nixos.org@grahamc:nixos.orginteresting13:21:19
@grahamc:nixos.org@grahamc:nixos.orgnot sure you can actually13:21:38
@grahamc:nixos.org@grahamc:nixos.orgmaybe you can13:21:44
@grahamc:nixos.org@grahamc:nixos.orgbut I'm thinking about how the bios can wipe it too13:24:08
@andi:kack.itandi-That would mean that I must lock the tpm device away and only let root / a special user interact with it.13:24:25
@andi:kack.itandi-I read some text that said that there are some hardware keys to adjust it13:24:38
@grahamc:nixos.org@grahamc:nixos.orgyou sort of need to do that anyway13:25:12
@grahamc:nixos.org@grahamc:nixos.orgbecause the nvram isn't partitioned or anything, it has no fs, you just have offsets in to the memory you write to13:25:35
@andi:kack.itandi-So you need to coordinate offsets across all your tools? e.g. OpenConnect and my kerberos daemon must each know where they can write?13:26:50
@grahamc:nixos.org@grahamc:nixos.orgmostly tools dont' need to write to the nvram I think13:27:15
@grahamc:nixos.org@grahamc:nixos.orglike, I think the nvram is for "I don't have a filesystem yet!" stuff, plus perhaps password attempt counters13:27:35

Show newer messages


Back to Room ListRoom Version: 6