!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
1 Mar 2023
@raitobezarius:matrix.orgraitobezarius2.6.1, 2.6.2, 2.6.313:18:10
@raitobezarius:matrix.orgraitobezariusIt's indeed the "reference code" provided in the specification13:18:27
@grahamc:nixos.org@grahamc:nixos.orgah, ok, cool, so the code is in the spec, but as a reference and not actually the rules of how a tpm must operate13:18:53
@raitobezarius:matrix.orgraitobezariusYeah, it's not protocol-level vuln I suppose13:19:03
@grahamc:nixos.org@grahamc:nixos.orgwhew13:19:28
@raitobezarius:matrix.orgraitobezarius cc baloo if you can bump libtpms in nixpkgs 13:34:23
@baloo_:matrix.orgbaloo Yeah the spec also provide a sample implementation. I know libtpms just imports that.
I don’t know if the spec mandates that you use this implementation
15:24:11
@baloo_:matrix.orgbalooWhat I can tell you is that it is sometimes easier to go look at the code to make sense of the spec (especially around credentials)15:24:48
@baloo_:matrix.orgbaloo Yeah I’ll bump the libtpms 15:26:28
@baloo_:matrix.orgbaloohttps://github.com/NixOS/nixpkgs/pull/21901616:34:32
@baloo_:matrix.orgbaloonow the fun begins: sending that to vendors of TPMs and see if they are affected :D16:54:40
@baloo_:matrix.orgbaloogot beat to it, but I don't think I can share the response from vendor. But I can say our product is not affected?17:06:43
@baloo_:matrix.orgbaloomake of that what you will17:06:51
@js:ukvly.orgJulian Stecklina (Old) baloo: where are you actually working at? :) (If you want to share) 17:15:42
@baloo_:matrix.orgbalooarista networks17:15:56
@baloo_:matrix.orgbaloothe NDR division deploys nixos in production17:16:58
@js:ukvly.orgJulian Stecklina (Old)Ah, nice17:17:07
2 Mar 2023
@j-k:matrix.orgj-k joined the room.11:52:10
9 Mar 2023
@redstone-menace:matrix.orgR̴̨͕͇͍̞̮̐̅͆̌̀̉̐͋̈́̃̀͒́̎̅̚̚̚͠͝Ĕ̵̡̛͖͖̟̙̫̱͈̘̞̭͍͍͑̌̄͑̓̋̓̀̈̏̈́͊̇͊͆̉͂̏̀̃̚͘͝͝ͅͅD̶̡̢͔̱̖̮͙͉̘̺͓͍̩̮͈͍͗̃̀̏͌͘͜ͅŚ̸̬̭̯̬͙͇͓̬̩̳̤͚͓̤̩̺͉͖̉͛̓̿̎͊̿̆́̐͂̇͌̄̇̓͘ͅͅT̴̞̫̘̝͇͔̟̪̪̦͂̔̎̀̎ͅŎ̷̡̬̹̪͈̭̣͈̭̭͉̦̖̝̘̪͖͔̥̦̘̻̳Ṋ̶̛̫͈̳̘͚̜̔̋͆̅̈́͊̑͊̉̌̈́̾͑̈́̚ͅË̸̡̨̨̛͇̜̖͔͖̻̟̗̠̙͓̘̗̥͉͇̜͑͆͊͑͑̀̓͒͜͝͝ joined the room.05:00:39
@pedrohlc:mozilla.orgpedrohlc changed their profile picture.13:30:25
14 Mar 2023
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them) to ckie (they/them; heavily limited keyboard usage, dictation or voice only).01:10:19
15 Mar 2023
@Cornu:matrix.orgcornu joined the room.21:14:25
19 Mar 2023
@quasineutral:matrix.orgquasineutral joined the room.11:44:55
23 Mar 2023
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them; heavily limited keyboard usage, dictation or voice only) to ckie (they/them; limited keyboard usage, voice preferred).02:05:13
2 Apr 2023
@aktaboot:tchncs.deaktaboot left the room.17:13:08
16 Apr 2023
@ianluo001:matrix.orgian luo joined the room.02:27:17
17 Apr 2023
@genericnerdyusername:matrix.orgGenericNerdyUsername joined the room.22:56:18
28 Apr 2023
@raitobezarius:matrix.orgraitobezarius ElvishJerricco: so you have TPM2 unlock with systemd-measure for PCRs? 13:06:47
@elvishjerricco:matrix.orgElvishJerricco raitobezarius: Yea, using https://github.com/DeterminateSystems/bootspec-secureboot/pull/240 13:10:49
@raitobezarius:matrix.orgraitobezariusalright I might port this to lanzaboote13:17:10

Show newer messages


Back to Room ListRoom Version: 6