!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
28 Apr 2023
@baloo_:matrix.orgbalooother than that, it's a plain hash of the file.17:33:34
@baloo_:matrix.orgbaloo( https://github.com/m4b/goblin/pull/362/files )17:34:54
8 May 2023
@pedrohlc:mozilla.org@pedrohlc:mozilla.org changed their profile picture.13:33:33
12 May 2023
@samueldr:matrix.org@samueldr:matrix.org changed their profile picture.02:29:46
@lassulus:lassul.uslassulus changed their profile picture.10:12:06
@lassulus:lassul.uslassulus changed their profile picture.13:39:13
14 May 2023
@sympt:matrix.orgsympt joined the room.07:33:28
15 May 2023
@genericnerdyusername:matrix.orgGenericNerdyUsername idk if this is more of a question for https://matrix.to/#/#secure-boot:nixos.org, but https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ says PCR 7 changes when UEFI SecureBoot mode is enabled/disabled, or firmware certificates (PK, KEK, db, dbx, …) are updated. The shim project will measure most of its (non-MOK) certificates and SBAT data into this PCR. 20:38:49
@genericnerdyusername:matrix.orgGenericNerdyUsernameWhat do I do if I want to update the dbx?20:39:15
@genericnerdyusername:matrix.orgGenericNerdyUsername * What do I do if I want to update the dbx, but have a key sealed against PCR7?20:40:34
@genericnerdyusername:matrix.orgGenericNerdyUsername * idk if this is more of a question for https://matrix.to/#/#secure-boot:nixos.org, but https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ says PCR 7 changes when UEFI SecureBoot mode is enabled/disabled, or firmware certificates (PK, KEK, db, dbx, …) are updated. 20:40:43
@genericnerdyusername:matrix.orgGenericNerdyUsernameOr rather, how do I prevent this being a problem in the future?20:41:06
@genericnerdyusername:matrix.orgGenericNerdyUsername(Im setting up full disk encryption with the key stored in the tpm)20:41:18
@js:ukvly.orgJulian Stecklina (Old)As long as you have another key to unlock the volume and reenroll its key, you should be fine 21:41:09
@baloo_:matrix.orgbaloohttps://trustedcomputinggroup.org/wp-content/uploads/TCG_TPM2_r1p59_Part1_Architecture_pub.pdf#page=158 :)21:43:28
@baloo_:matrix.orgbaloojust add another layer of crypto21:44:26
@baloo_:matrix.orgbaloonow you just need to add support for EA policies to ... everything?21:45:46
25 May 2023
@raitobezarius:matrix.orgraitobezarius changed their display name from raitobezarius to disko in NixOS 23.11 when.13:32:34
@raitobezarius:matrix.orgraitobezarius changed their display name from disko in NixOS 23.11 when to raitobezarius.13:37:35
27 May 2023
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.16:40:45
1 Jun 2023
@federicodschonborn:matrix.org@federicodschonborn:matrix.org joined the room.11:58:28
2 Jun 2023
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them; limited keyboard usage, voice preferred) to ckie (they/them).22:21:24
4 Jun 2023
@eliaselias:matrix.orgeliaselias joined the room.09:05:47
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their profile picture.17:40:15
13 Jun 2023
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their profile picture.20:55:36
14 Jun 2023
@ronnypfannschmidt:matrix.org@ronnypfannschmidt:matrix.org left the room.15:14:41
25 Jun 2023
@hexa:lossy.networkhexahttps://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-4j3v-fh23-vx6722:56:37
26 Jun 2023
@raitobezarius:matrix.orgraitobezarius baloo: ^ 08:32:23
27 Jun 2023
@baloo_:matrix.orgbaloowait, opened since Jan 19?!03:31:52
@baloo_:matrix.orgbaloofixed in 4.0.103:33:20

Show newer messages


Back to Room ListRoom Version: 6