!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

181 Members
49 Servers

Load older messages


SenderMessageTime
15 May 2023
@genericnerdyusername:matrix.orgGenericNerdyUsername * idk if this is more of a question for https://matrix.to/#/#secure-boot:nixos.org, but https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ says PCR 7 changes when UEFI SecureBoot mode is enabled/disabled, or firmware certificates (PK, KEK, db, dbx, …) are updated. 20:40:43
@genericnerdyusername:matrix.orgGenericNerdyUsernameOr rather, how do I prevent this being a problem in the future?20:41:06
@genericnerdyusername:matrix.orgGenericNerdyUsername(Im setting up full disk encryption with the key stored in the tpm)20:41:18
@js:ukvly.orgJulian StecklinaAs long as you have another key to unlock the volume and reenroll its key, you should be fine 21:41:09
@baloo_:matrix.orgbaloohttps://trustedcomputinggroup.org/wp-content/uploads/TCG_TPM2_r1p59_Part1_Architecture_pub.pdf#page=158 :)21:43:28
@baloo_:matrix.orgbaloojust add another layer of crypto21:44:26
@baloo_:matrix.orgbaloonow you just need to add support for EA policies to ... everything?21:45:46
25 May 2023
@raitobezarius:matrix.orgraitobezarius changed their display name from raitobezarius to disko in NixOS 23.11 when.13:32:34
@raitobezarius:matrix.orgraitobezarius changed their display name from disko in NixOS 23.11 when to raitobezarius.13:37:35
27 May 2023
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.16:40:45
1 Jun 2023
@federicodschonborn:matrix.orgFederico Damián Schonborn joined the room.11:58:28
2 Jun 2023
@ckie:ckie.devckie (they/them) changed their display name from ckie (they/them; limited keyboard usage, voice preferred) to ckie (they/them).22:21:24
4 Jun 2023
@eliaselias:matrix.orgeliaselias joined the room.09:05:47
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their profile picture.17:40:15
13 Jun 2023
@federicodschonborn:matrix.orgFederico Damián Schonborn changed their profile picture.20:55:36
14 Jun 2023
@ronnypfannschmidt:matrix.orgRonny left the room.15:14:41
25 Jun 2023
@hexa:lossy.networkhexahttps://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-4j3v-fh23-vx6722:56:37
26 Jun 2023
@raitobezarius:matrix.orgraitobezarius baloo: ^ 08:32:23
27 Jun 2023
@baloo_:matrix.orgbaloowait, opened since Jan 19?!03:31:52
@baloo_:matrix.orgbaloofixed in 4.0.103:33:20
@baloo_:matrix.orgbaloosome idiot patched tpm2-tss to wire in the modules with their full path ><15:38:38
@baloo_:matrix.orgbalooI can't remember how I was running tests manually15:38:49
@hexa:lossy.networkhexacan someone update it?15:47:08
@hexa:lossy.networkhexawe are on 3.2.0 on master15:47:12
@baloo_:matrix.orgbalooyeah yeah, I'm working on it15:47:18
@baloo_:matrix.orgbaloo(I'm the idiot I was referring to previously)15:47:33
@hexa:lossy.networkhexagood luck with yourself15:47:52
@hexa:lossy.networkhexahope they learn15:47:56
@baloo_:matrix.orgbaloosome of the challenge with tpm2-tss is the pluggable backends15:48:09
@baloo_:matrix.orgbaloo you load tabrmd and that will load PREFIX/lib/libtss2-tcti-tabrmd.so.0 15:48:45

Show newer messages


Back to Room ListRoom Version: 6