!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
27 Jul 2023
@ribosomerocker:matrix.orgribosomerocker joined the room.02:59:22
31 Jul 2023
@baloo_:matrix.orgbalooCould someone merge that one for me? https://github.com/NixOS/nixpkgs/pull/24596204:03:54
9 Aug 2023
@gkleen:synapse.ligkleen joined the room.10:41:36
13 Aug 2023
@10leej:matrix.orgnevoyu joined the room.01:24:55
15 Aug 2023
@10leej:matrix.orgnevoyu left the room.19:34:10
18 Aug 2023
@shados:nixos.devShados joined the room.05:42:10
@zeorin:matrix.orgXandor Schiefer joined the room.09:15:44
19 Aug 2023
@khalilsantana:matrix.orgkhalil left the room.19:50:07
31 Aug 2023
@philiptaron:matrix.orgPhilip Taron (UTC-8) joined the room.21:47:01
9 Sep 2023
@msanft:matrix.orgMoritz Sanft joined the room.12:13:37
16 Sep 2023
@majiir:matrix.orgMajiir Paktu joined the room.00:04:45
@arkivm:matrix.orgarkivmI have sent an RFC for keylime and its services here: https://github.com/NixOS/nixpkgs/pull/255540 any feedback would be appreciated. 22:39:51
17 Sep 2023
@raitobezarius:matrix.orgraitobezarius arkivm: wouldn't it be better to have keylime-agent and keylime as two differen tservices? 11:39:36
@raitobezarius:matrix.orgraitobezariusyou want to run the agent on clients11:39:39
@raitobezarius:matrix.orgraitobezariusthe rest on servers11:39:43
@raitobezarius:matrix.orgraitobezariusalso this service is non-configurable and use all presets from the package themselves11:40:25
@raitobezarius:matrix.orgraitobezariusminimally, we should have settings option for each relevant configuration file11:40:36
18 Sep 2023
@arkivm:matrix.orgarkivm raitobezarius: That's how I initially started. Right now, services.keylime.enable doesn't turn on any services. You can selectively pick services.keylime.<keylime_modules>.enable where keylime_modules can be agent, registrar and verifier. But if you think splitting it into two modules (one for agent and the rest as one) has better modularity, I can split them. 04:45:33
@arkivm:matrix.orgarkivmI don't have much experience running keylime in production. I have played around with it only in local experimental setup. But, I agree that the default options may not be what everyone wants. What options should be configurable? Do you have some insights?04:48:19
@arkivm:matrix.orgarkivmUpdated the PR by separating agent and the rest.06:32:39
@raitobezarius:matrix.orgraitobezariusI am not sure keylime should be packaged in nixpkgs, especially if you don't plan to have production usage07:53:03
@raitobezarius:matrix.orgraitobezariusIt makes more sense to wait for someone who have expert knowledge rather than rush and package something that's meh in terms of security for such a piece of software07:53:23
21 Sep 2023
@dedmunwalk:matrix.orgdedmunwalk joined the room.23:06:14
23 Sep 2023
@elvishjerricco:matrix.orgElvishJerriccoThis isn't exactly NixOS, but I'm trying to test out Ubuntu's new TPM based FDE in a libvirt VM, but the TPM entered DA lockout mode during installation, and I'm not sure how to get it out of it. When my Steam Deck entered lockout, I just had to wait 15mins, but no amount of waiting (up to several hours) has helped here.06:18:21
@elvishjerricco:matrix.orgElvishJerricco

oh, well deleting the VM and starting anew, the installation failure isn't what I thought: cannot seal the encryption keys: cannot add EFI secure boot policy profile: cannot compute secure boot policy profile: the current boot was preceeded by a boot attempt to an EFI application that returned to the boot manager, without a reboot in between

(I enrolled MS secure boot keys with sbctl from a nixos ISO, but there was a hard shutoff before booting into the ubuntu ISO)

07:19:43
@elvishjerricco:matrix.orgElvishJerricco and after that installation failure, the swtpm is in lockout mode 07:20:20
@elvishjerricco:matrix.orgElvishJerriccoso I wonder if libvirt isn't shutting down swtpm correctly07:20:38
@snuupy:matrix.orgSnuupy joined the room.10:17:56
@elvishjerricco:matrix.orgElvishJerriccoHuh, apparently I had to make sure the installation disk was first in the boot order. Attempting and failing to boot the empty hard drive messed with the secure boot measurements or something19:51:37
24 Sep 2023
@flokli:matrix.orgflokliThis smells like a firmware issue/mistake a bunch of vendors initially did as well08:02:10

Show newer messages


Back to Room ListRoom Version: 6