| 24 Sep 2023 |
ElvishJerricco | flokli: yea that's rough if OVMF has this bug :P | 20:48:48 |
flokli | maybe that | 22:07:33 |
flokli | * maybe that's why it's broken in all vendor firmwares ;-) | 22:07:41 |
flokli | * maybe that's why it is/was broken in all vendor firmwares ;-) | 22:07:50 |
| 25 Sep 2023 |
| bertof joined the room. | 10:43:50 |
baloo | Scream if you need us to send water or food down there | 18:17:21 |
| maka-77x joined the room. | 23:24:13 |
| 26 Sep 2023 |
@roosemberth:orbstheorem.ch | I was reading lanzaboote's readme:
> An optimistic plan is to have a "in-tree" feature preview of Lanzaboote as part of NixOS 23.11.
:D | 04:25:48 |
@roosemberth:orbstheorem.ch | Anywho, I would like to understand exactly what measurements go into what TPM registry and where it's implemented (firmware, lanzaboote-stub, kernel or anything really). | 04:28:59 |
| 28 Sep 2023 |
ElvishJerricco | In reply to @roosemberth:orbstheorem.ch Anywho, I would like to understand exactly what measurements go into what TPM registry and where it's implemented (firmware, lanzaboote-stub, kernel or anything really). https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ | 06:23:40 |
raitobezarius |
18:32 ▬▬▶ jakogut (~oftc-webi@172-223-248-144.res.spectrum.com) a rejoint #edk2 18:36 <jakogut> Hello, I'm working on a Linux-based OS integrating secure boot and disk encryption using the TPM to encrypt the LUKS passphrase. It's working with a NUC, but with QEMU and OVMF, the digest of PCR7 isn't matching what I expect. Strangely, it seems the TPM event log isn't created in securityfs in QEMU. Even stranger, booting an Arch ISO with the exact same QEMU config creates it just fine. 18:39 <jakogut> Reviewing the kernel logs, it seems the only difference is the line starting with "efi:" on the system with the working event log shows the address of TPMEventLog in addition to TPMFinalLog, whereas the non-working system shows only "TPMFinalLog". 18:40 <jakogut> Any ideas on what may be going wrong here? If I can get the TPM event log working on this QEMU system, it'll get me a lot closer to debugging the unexpected PCR hash.
| 19:49:16 |
raitobezarius | very fresh from #edk2 | 19:49:19 |
| 30 Sep 2023 |
| Andreas Fjärrwall joined the room. | 21:05:53 |