| 16 Jul 2021 |
@grahamc:nixos.org | you don't need any special credential to use the roots | 12:15:55 |
@grahamc:nixos.org |
I am still a bit confused by the requirement of different secrets to decrypt one secret.
| 12:16:49 |
andi- | Does the internal seed change the PCR values? I guess it shouldn't... | 12:16:54 |
@grahamc:nixos.org | I think this is because you're maybe not ever going to decrypt it | 12:16:56 |
@grahamc:nixos.org | but maybe you're just using it for attestation | 12:17:07 |
@grahamc:nixos.org | I don't think the seed has anything to do with the PCR, yeah | 12:18:16 |
@grahamc:nixos.org | Redacted or Malformed Event | 12:19:07 |
@grahamc:nixos.org | ah here we are | 12:20:30 |
@grahamc:nixos.org | you can get what the TPM calls a "quote" which is the PCRs signed by the TPM, in a way you can trust itis actually the PCRs and not falsified | 12:21:03 |
@grahamc:nixos.org | https://www.mankier.com/1/tpm2_quote | 12:21:10 |
| Linux Hackerman is moving: @linus:schreibt.jetzt joined the room. | 12:21:36 |
andi- | I must also look at the OpenConnect VPN client. Apparently they integrate with the kernel keyring but there are also mentions of the TSS lib somewhere. Perhaps that stuff is really interoperable. At first I didn't think that could be the case. | 12:22:58 |
@grahamc:nixos.org | I wonder if the openconnect server can require your PCRs to match specific values to allow a connection | 12:24:00 |
| Matrix Traveler (bot) joined the room. | 12:24:04 |
@grahamc:nixos.org | * I wonder if the openconnect client key can require your PCRs to match specific values to allow a connection | 12:24:11 |
andi- | Off-topic: Do we now have all the bots on the matrix universe? :D | 12:24:22 |
@grahamc:nixos.org | I would not be surprised if that were true, the TPM2 book talks about it a lot :D | 12:24:22 |
@grahamc:nixos.org | haha | 12:24:33 |
andi- | It is nice that we have a well documented user of all of the TPM infrastructure. | 12:41:49 |
| hexa joined the room. | 12:41:58 |
andi- | I now wish that I could use the TPM for wireguard key derivation. | 12:41:58 |
@grahamc:nixos.org | is that openconnect? | 12:42:04 |
andi- | Yeah | 12:42:10 |
@grahamc:nixos.org | :) | 12:42:14 |
| spacesbot - keeps a log of public NixOS channels | 13:00:04 |
andi- | So yesterday I was able to wipe my state without th ecorrect password IIRC. All I did was call tpm2_clear. | 13:16:47 |
andi- | How do you protect against that? | 13:17:04 |
andi- | IIRC I did set two passwords when I first setup secrets. | 13:17:24 |
@grahamc:nixos.org | interesting | 13:21:19 |
@grahamc:nixos.org | not sure you can actually | 13:21:38 |