!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

178 Members
43 Servers

Load older messages


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.orgit would probably need to be an opinionated thing13:56:29
@grahamc:nixos.org@grahamc:nixos.orglike "this won't work unless you follow our strict path =) my way or the highway "13:57:06
@andi:kack.itandi-Ok, I actually think Fedora has done that stuff. There is that dracut plugin that allows you to do SSS, Password, remote unlock and TPM based unlock etc..13:57:58
@grahamc:nixos.org@grahamc:nixos.orgalthough in what I've set up here I get PCR validation and encrypted disks without using nvram statue13:58:02
@grahamc:nixos.org@grahamc:nixos.org * although in what I've set up here I get PCR validation and encrypted disks without using nvram state13:58:12
@grahamc:nixos.org@grahamc:nixos.orgso it would only get wiped if they switched to windows and windows cleared the tpm13:58:31
@andi:kack.itandi-https://aboutcher.co.uk/2020/06/fedora-linux-luks-encryption-with-tpm-unlock/ this sounds so easy :D14:02:06
@hexa:lossy.networkhexaoh right, clevis.14:02:51
@andi:kack.itandi-Getting clevis to work on NixOS would already be amazing. SSS for unlocking a community computer is a common enough use case.14:03:33
@hexa:lossy.networkhexaright, that's when we looked into that14:03:59

There are no newer messages yet.


Back to Room ListRoom Version: 6