!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

172 Members
43 Servers

Load older messages


SenderMessageTime
6 Jan 2023
@bbigras:matrix.org@bbigras:matrix.org left the room.06:19:02
18 Jan 2023
@fabianhjr:matrix.orgFabián Heredia joined the room.03:52:48
@js:ukvly.orgJulian Stecklina (Old)hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?13:19:14
@me:linj.techlinj
In reply to @js:ukvly.org
hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?
https://trustedcomputinggroup.org/resource/pc-client-specific-platform-firmware-profile-specification/
13:30:05
@js:ukvly.orgJulian Stecklina (Old)Thanks! 👍17:48:47
@elvishjerricco:matrix.orgElvishJerricco Julian Stecklina: for something much more Linux specific, check the man page for systemd-cryptenroll 23:38:32
19 Jan 2023
@ronnypfannschmidt:matrix.org@ronnypfannschmidt:matrix.org changed their profile picture.08:34:25
20 Jan 2023
@emantor:stratum0.org@emantor:stratum0.org left the room.09:23:52
28 Jan 2023
@elvishjerricco:matrix.orgElvishJerricco

https://github.com/systemd/systemd/pull/26185

This sounds like you won't be able to just systemd-cryptenroll with a TPM anymore without taking ownership of the TPM, is that right?

18:05:20
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: ^ This might be relevant for us with our Steam Deck set ups. 18:09:40
@zhaofeng:zhaofeng.liZhaofeng LiHmm possibly, we should ask18:37:54
30 Jan 2023
@elvishjerricco:matrix.orgElvishJerricco

If the owner auth is empty, you have a worthless TPM

Can anyone explain what they mean by this?

21:12:41
31 Jan 2023
@baloo_:matrix.orgbalooHis concerns seems to be that someone would be able to nuke the keys.17:37:21
@baloo_:matrix.orgbaloo(you need to auth with the password for the lockout hierarchy to issue a tpm clear on the owner hierarchy)17:38:03
@baloo_:matrix.orgbaloo not entirely sure what the owner auth refers to? You'd need that to tpm2_nvundefine I guess? 17:39:22
@baloo_:matrix.orgbalooif you want a sandbox to play with that: https://gist.github.com/baloo/dcc7dc2405063a151ca527b79893170c17:43:16
1 Feb 2023
@grahamc:nixos.org@grahamc:nixos.orgwhat's a few nuked keys between friends14:59:43
2 Feb 2023
@elvishjerricco:matrix.orgElvishJerricco baloo: I'm still very confused about what that PR actually does, and the author was very dismissive and unhelpful when I asked. 15:30:46
@baloo_:matrix.orgbaloo Yeah that’s the curse of tpm I guess. Everyone has an opinion but everyone is always wrong. Except mjg59 16:30:52
@elvishjerricco:matrix.orgElvishJerricco baloo: Yea it was mentioned to me that that person might have a good explanation about TPM stuff somewhere but I didn't really find anything browsing their blog 19:16:20
@elvishjerricco:matrix.orgElvishJerriccoI mean I saw some stuff basically outlining measured boot and whatnot but that's not really what I'm not understanding19:16:54
@baloo_:matrix.orgbaloowho's that?19:16:57
@elvishjerricco:matrix.orgElvishJerriccomjg19:17:06
@raitobezarius:matrix.orgraitobezariusmjg5919:17:07
@baloo_:matrix.orgbalooha, yeah. well I do enjoy his fediverse's feed19:17:43
@baloo_:matrix.orgbaloo * ha, yeah. well I do enjoy his fediverse feed19:17:50
@matthewp:matrix.orgMatthew joined the room.21:44:55
3 Feb 2023
@flokli:matrix.orgflokliI tried backporting the systemd tpm fixes into the current stable release, but tripped an assertion: https://github.com/NixOS/nixpkgs/pull/21438316:54:57
4 Feb 2023
@elvishjerricco:matrix.orgElvishJerriccoThis ended up being incredibly helpful for my SRK questions and generally does a good job explaining all aspects of the TPM at a high level: https://google.github.io/tpm-js/03:19:46
20 Feb 2023
@mixis:bau-ha.usmixis set a profile picture.18:09:00

Show newer messages


Back to Room ListRoom Version: 6