!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
16 Jul 2021
@andi:kack.itandi-You can also follows this guide: https://incenp.org/notes/2020/tpm-based-ssh-key.html minus all the compiling16:40:11
@andi:kack.itandi- Mic92: are you aware of a password manager that uses pkcs11 and isn't using GPG? Age is still not able to do that IIRC. 16:43:58
@andi:kack.itandi-(It has a bunch of repos around that topic but I've not managed to understand why they need so many)16:44:04
@samueldr:matrix.org@samueldr:matrix.org joined the room.18:19:34
@grahamc:nixos.org@grahamc:nixos.orgI think it would go a long way if someone made some flow charts of how pieces fit together and some state diagrams,18:46:44
@grahamc:nixos.org@grahamc:nixos.orglike a state diagram of the lockout interval, recovery, counter for example. it is not very complicated, but I think a diagram would clear up how it is used18:48:07
@andi:kack.itandi-Is there a nice collaborative tool to draw those?18:57:14
@andi:kack.itandi-I don't want to pass graphviz files around18:57:28
@grahamc:nixos.org@grahamc:nixos.orgI was just going to say graphviz18:57:35
@andi:kack.itandi-how about https://md.darmstadt.ccc.de/tpm2# ?18:59:52
@andi:kack.itandi-It is graphviz and collaborative18:59:58
@grahamc:nixos.org@grahamc:nixos.orgoh wowo19:00:37
@grahamc:nixos.org@grahamc:nixos.orgnice19:00:54
@andi:kack.itandi-There you go :P19:01:07
@grahamc:nixos.org@grahamc:nixos.orgpage 67 TPM_PT_LOCKOUT_RECOVERY https://trustedcomputinggroup.org/wp-content/uploads/TPM-Rev-2.0-Part-2-Structures-01.38.pdf19:23:51
@grahamc:nixos.org@grahamc:nixos.orgnot pointing anything out there just a primary source for the meaning of these values19:26:30
@grahamc:nixos.org@grahamc:nixos.org removed the room topic "Exploring TPMs on NixOS".19:31:12
@grahamc:nixos.org@grahamc:nixos.org andi-: should I change the main address to be #tpm:nixos.org? 19:37:09
@andi:kack.itandi-Sure19:37:56
@grahamc:nixos.org@grahamc:nixos.orgI'm a little confused, failedTries hasn't decremented despite recoveryTime elapsing several times19:42:47
@grahamc:nixos.org@grahamc:nixos.orgso, seeing this happen I decided to look at the spec19:45:54
@grahamc:nixos.org@grahamc:nixos.org
failedTries(NV) –This counter is incremented when the TPM returns TPM_RC_AUTH_FAIL. TPM2_Clear() will reset this counter to zero. This counter is also set to zero on a successful invocation of TPM2_DictionaryAttackLockReset(). This counter is decremented by one after recoveryTimeseconds if:the TPM does not record an authorization failure of a DA-protected entity,there is no power interruption, andfailedTriesis not zero
19:46:14
@grahamc:nixos.org@grahamc:nixos.orgI think I have errata lol19:47:56
@grahamc:nixos.org@grahamc:nixos.org andi-: do you have a handy tpm simulator's source link? 19:51:04
@andi:kack.itandi-One sec I read that earlier somewhere. If you use libvirt that is supposed to just work but with QEMU you have to launch a daemon..19:51:37
@andi:kack.itandi-https://documentation.suse.com/sles/15-SP3/html/SLES-all/tpm.html19:52:04
@grahamc:nixos.org@grahamc:nixos.orghm19:58:23
@grahamc:nixos.org@grahamc:nixos.organnoying20:01:01
@grahamc:nixos.org@grahamc:nixos.organd I'm sort of out of energy to dig in to this to see why it isn't decrementing20:01:12
@grahamc:nixos.org@grahamc:nixos.orgbut I suppose it has to do wit this:20:01:15

Show newer messages


Back to Room ListRoom Version: 6