!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
1 Dec 2022
@hexa:lossy.networkhexa changed their display name from hexa to hexa (22.11 now).13:08:46
@hexa:lossy.networkhexa changed their display name from hexa (22.11 now) to hexa.14:38:34
3 Dec 2022
@raitobezarius:matrix.orgraitobezariusDid someone already configured a NitroKey HSM2 on NixOS ?18:30:29
@raitobezarius:matrix.orgraitobezariusI guess there's some udev stuff to install, etc. ?18:30:35
@raitobezarius:matrix.orgraitobezariusOpenSC is not recognizing the card18:30:40
* @raitobezarius:matrix.orgraitobezarius is going to use SecureBoot with a HSM because it is fun18:30:54
@raitobezarius:matrix.orgraitobezarius

great, pcscd seems to have done the trick:

Using reader with a card: Nitrokey Nitrokey HSM (DENK03003700000         ) 00 00
Version              : 3.5
SmartCard-HSM has never been initialized. Please use --initialize to set SO-PIN and user PIN.
18:42:16
@flokli:matrix.orgflokliHeeh, nice20:10:35
4 Dec 2022
@schnecfk:ruhr-uni-bochum.deCRTified (old handle) changed their display name from CRTified to CRTified (old handle).14:19:13
6 Dec 2022
@schnecfk:ruhr-uni-bochum.deCRTified (old handle) changed their profile picture.14:11:40
22 Dec 2022
@da:esclear.deDaniel removed their profile picture.17:22:42
@da:esclear.deDaniel removed their display name Daniel.17:24:44
@da:esclear.deDaniel left the room.17:26:10
25 Dec 2022
@ahsmha:matrix.orgahmed left the room.10:39:55
30 Dec 2022
@crtified:crtified.meCRTified joined the room.10:11:29
@schnecfk:ruhr-uni-bochum.deCRTified (old handle) left the room.10:11:34
1 Jan 2023
@v0id:nltrix.netv0|d left the room.12:05:17
@void68:matrix.orgvoid joined the room.17:39:52
@void68:matrix.orgvoid set a profile picture.18:07:49
2 Jan 2023
@pedrohlc:mozilla.orgpedrohlc joined the room.19:06:00
6 Jan 2023
@bbigras:matrix.orgbbigras left the room.06:19:02
18 Jan 2023
@fabianhjr:matrix.orgFabián Heredia joined the room.03:52:48
@js:ukvly.orgJulian Stecklina (Old)hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?13:19:14
@me:linj.techlinj
In reply to @js:ukvly.org
hey everyone. Is there a good overview somewhere what the different TPM PCRs are usually used for?
https://trustedcomputinggroup.org/resource/pc-client-specific-platform-firmware-profile-specification/
13:30:05
@js:ukvly.orgJulian Stecklina (Old)Thanks! 👍17:48:47
@elvishjerricco:matrix.orgElvishJerricco Julian Stecklina: for something much more Linux specific, check the man page for systemd-cryptenroll 23:38:32
19 Jan 2023
@ronnypfannschmidt:matrix.orgRonny changed their profile picture.08:34:25
20 Jan 2023
@emantor:stratum0.orgEmantor left the room.09:23:52
28 Jan 2023
@elvishjerricco:matrix.orgElvishJerricco

https://github.com/systemd/systemd/pull/26185

This sounds like you won't be able to just systemd-cryptenroll with a TPM anymore without taking ownership of the TPM, is that right?

18:05:20
@elvishjerricco:matrix.orgElvishJerricco Zhaofeng Li: ^ This might be relevant for us with our Steam Deck set ups. 18:09:40

Show newer messages


Back to Room ListRoom Version: 6