!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

171 Members
44 Servers

Load older messages


SenderMessageTime
12 Dec 2024
@numinit:matrix.orgMorgan (@numinit)No problem, this will be super useful for the nixPKCS test suite 04:14:27
@numinit:matrix.orgMorgan (@numinit)Really appreciate the change! 04:14:34
@baloo_:matrix.orgbalooYeah that makes my test suite a lot more easy to run too04:15:11
@baloo_:matrix.orgbaloomuch easier than having to pull real hardware04:15:25
@numinit:matrix.orgMorgan (@numinit)I was going to add attestation support eventually to https://github.com/numinit/nixpkcs - this is a kick in the pants for me to do it04:15:46
@numinit:matrix.orgMorgan (@numinit) Someone just got step-ca working with it though, which is encouraging 04:16:40
@baloo_:matrix.orgbalooFriends don't let people use pkcs1104:16:49
@numinit:matrix.orgMorgan (@numinit)hah04:16:56
@baloo_:matrix.orgbaloo(I hate pkcs11 dearly)04:17:15
@numinit:matrix.orgMorgan (@numinit) Brutally hard to wrap things with, I do too. Had to do passthrus for it all 04:17:31
@numinit:matrix.orgMorgan (@numinit)This does actually make it easier, though through the brute force of injecting support into OpenSSL04:18:14
@baloo_:matrix.orgbalooyeah, looks like you figured out a bunch of options in a bunch of very useful tools04:19:05
@numinit:matrix.orgMorgan (@numinit) Basically, yeah. 04:19:18
@baloo_:matrix.orgbalooI guess you ended up full of yak hair after doing that04:19:21
@baloo_:matrix.orgbaloo(thanks for doing that)04:19:45
@baloo_:matrix.orgbalooor full of weeds I guess04:19:57
@numinit:matrix.orgMorgan (@numinit)yeah, pretty much - declarative definition of yubikeys is pretty cool at least04:19:58
@numinit:matrix.orgMorgan (@numinit)though I completely understand why wo one supported PKCS11 now - it's a pain in the @$$04:20:50
@baloo_:matrix.orgbaloohave you had the delight to work HSM vendors already?04:20:55
@numinit:matrix.orgMorgan (@numinit)* though I completely understand why no one supported PKCS11 now - it's a pain in the @$$04:20:56
@numinit:matrix.orgMorgan (@numinit) ... yep. 04:21:10
@numinit:matrix.orgMorgan (@numinit)Different tools for everything04:21:21
@baloo_:matrix.orgbaloocondolences 04:21:23
@numinit:matrix.orgMorgan (@numinit)I'm surprised PKCS#11 can even generate keys04:21:48
@numinit:matrix.orgMorgan (@numinit)support apparently has been recently improving in general with AWS and Google's cloud HSMs04:22:19
@baloo_:matrix.orgbalooha yeah, the easy ones :D04:22:36
@numinit:matrix.orgMorgan (@numinit)when the standard says something is optional, no one implements it04:22:44
@baloo_:matrix.orgbaloowait until you use the thales or entrust ones :D04:23:02
@baloo_:matrix.orgbaloo(don't use entrust)04:23:09
@numinit:matrix.orgMorgan (@numinit)lol, qualcomm low level bringup has been my recent 😢04:23:27

Show newer messages


Back to Room ListRoom Version: 6