!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

172 Members
43 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
1 Jan 2023
@v0id:nltrix.net@v0id:nltrix.net left the room.12:05:17
@void68:matrix.orgvoid joined the room.17:39:52
@void68:matrix.orgvoid set a profile picture.18:07:49
2 Jan 2023
@pedrohlc:mozilla.org@pedrohlc:mozilla.org joined the room.19:06:00
6 Jan 2023
@bbigras:matrix.org@bbigras:matrix.org left the room.06:19:02
18 Jan 2023
@fabianhjr:matrix.orgFabián Heredia joined the room.03:52:48
@js:ukvly.orgJulian Stecklina (Old)hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?13:19:14
@me:linj.techlinj
In reply to @js:ukvly.org
hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?
https://trustedcomputinggroup.org/resource/pc-client-specific-platform-firmware-profile-specification/
13:30:05
@js:ukvly.orgJulian Stecklina (Old)Thanks! 👍17:48:47
@elvishjerricco:matrix.orgElvishJerricco Julian Stecklina: for something much more Linux specific, check the man page for systemd-cryptenroll 23:38:32
19 Jan 2023
@ronnypfannschmidt:matrix.org@ronnypfannschmidt:matrix.org changed their profile picture.08:34:25
20 Jan 2023
@emantor:stratum0.org@emantor:stratum0.org left the room.09:23:52
28 Jan 2023
@elvishjerricco:matrix.orgElvishJerricco

https://github.com/systemd/systemd/pull/26185

This sounds like you won't be able to just systemd-cryptenroll with a TPM anymore without taking ownership of the TPM, is that right?

18:05:20
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: ^ This might be relevant for us with our Steam Deck set ups. 18:09:40
@zhaofeng:zhaofeng.liZhaofeng LiHmm possibly, we should ask18:37:54
30 Jan 2023
@elvishjerricco:matrix.orgElvishJerricco

If the owner auth is empty, you have a worthless TPM

Can anyone explain what they mean by this?

21:12:41
31 Jan 2023
@baloo_:matrix.orgbalooHis concerns seems to be that someone would be able to nuke the keys.17:37:21
@baloo_:matrix.orgbaloo(you need to auth with the password for the lockout hierarchy to issue a tpm clear on the owner hierarchy)17:38:03
@baloo_:matrix.orgbaloo not entirely sure what the owner auth refers to? You'd need that to tpm2_nvundefine I guess? 17:39:22
@baloo_:matrix.orgbalooif you want a sandbox to play with that: https://gist.github.com/baloo/dcc7dc2405063a151ca527b79893170c17:43:16
1 Feb 2023
@grahamc:nixos.org@grahamc:nixos.orgwhat's a few nuked keys between friends14:59:43
2 Feb 2023
@elvishjerricco:matrix.orgElvishJerricco baloo: I'm still very confused about what that PR actually does, and the author was very dismissive and unhelpful when I asked. 15:30:46
@baloo_:matrix.orgbaloo Yeah that’s the curse of tpm I guess. Everyone has an opinion but everyone is always wrong. Except mjg59 16:30:52
@elvishjerricco:matrix.orgElvishJerricco baloo: Yea it was mentioned to me that that person might have a good explanation about TPM stuff somewhere but I didn't really find anything browsing their blog 19:16:20

Show newer messages


Back to Room ListRoom Version: 6