!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

172 Members
43 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
15 May 2023
@genericnerdyusername:matrix.orgGenericNerdyUsernameWhat do I do if I want to update the dbx?20:39:15
@genericnerdyusername:matrix.orgGenericNerdyUsername * What do I do if I want to update the dbx, but have a key sealed against PCR7?20:40:34
@genericnerdyusername:matrix.orgGenericNerdyUsername * idk if this is more of a question for https://matrix.to/#/#secure-boot:nixos.org, but https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ says PCR 7 changes when UEFI SecureBoot mode is enabled/disabled, or firmware certificates (PK, KEK, db, dbx, …) are updated. 20:40:43
@genericnerdyusername:matrix.orgGenericNerdyUsernameOr rather, how do I prevent this being a problem in the future?20:41:06
@genericnerdyusername:matrix.orgGenericNerdyUsername(Im setting up full disk encryption with the key stored in the tpm)20:41:18
@js:ukvly.orgJulian Stecklina (Old)As long as you have another key to unlock the volume and reenroll its key, you should be fine 21:41:09
@baloo_:matrix.orgbaloohttps://trustedcomputinggroup.org/wp-content/uploads/TCG_TPM2_r1p59_Part1_Architecture_pub.pdf#page=158 :)21:43:28
@baloo_:matrix.orgbaloojust add another layer of crypto21:44:26

Show newer messages


Back to Room ListRoom Version: 6