!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
18 Jul 2021
@grahamc:nixos.org@grahamc:nixos.org I wonder why getplatformcertificates is suddenly part of tss and not the tpm2 command 20:21:23
@andi:kack.itandi-the developers of tss needed it before they started the tpm2 tool?20:22:09
@grahamc:nixos.org@grahamc:nixos.orghm20:22:21
19 Jul 2021
@manveru:matrix.orgmanverudoes anyonne know if there's some way to turn tpm emulation on for a nixos test?06:23:46
@andi:kack.itandi-The current VM infrastructure doesnt allow that. You have to run an additional daemon 07:13:39
@mic92:nixos.dev@mic92:nixos.devCould you run two VMs for that?11:48:55
@andi:kack.itandi-No, you have to pass a socket to one of the daemons to QEMUs CLI. Forking off the software TPM before starting QEMU is probably good enough in a sandboxed test. For interactive testing you want more process control.11:49:44
@mic92:nixos.dev@mic92:nixos.devThere is some bridging possible with vsockets, but I guess it would get hacky11:50:04
@mic92:nixos.dev@mic92:nixos.devMaybe socat?11:50:10
@andi:kack.itandi-Yeah, probably but not very elegant. Would be nicer to teach our test driver to take care of "sidecars"11:50:31
@mic92:nixos.dev@mic92:nixos.devvsocket also need root with qemu I just remeber11:51:07
@mic92:nixos.dev@mic92:nixos.dev*remember11:51:12
@mic92:nixos.dev@mic92:nixos.devIt would be also nice for virtiofsd to have qemu side cars11:51:38

Show newer messages


Back to Room ListRoom Version: 6