!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

168 Members
42 Servers

Load older messages


SenderMessageTime
15 Sep 2022
@elvishjerricco:matrix.orgElvishJerriccooh yes01:36:57
@elvishjerricco:matrix.orgElvishJerriccoyes that's certainly true01:37:01
@elvishjerricco:matrix.orgElvishJerriccoI don't have a way to test that right now or else I'd try it out to make sure01:37:18
@elvishjerricco:matrix.orgElvishJerricco(one of the next things I'm going to do in my bootspec-secureboot adventure is add TPM support to qemu-vm so I can test that with NixOS tests as well)01:37:58
@elvishjerricco:matrix.orgElvishJerricco(but for now my steam deck is my only tpm enabled device and I very much do not have nixos on it yet)01:38:18
@zhaofeng:zhaofeng.liZhaofeng Li (as you mentioned - haven't checked the docs myself as I'm on my phone) 01:38:27
@elvishjerricco:matrix.orgElvishJerricco * (one of the next things I'm going to do in my bootspec-secureboot adventure is add TPM support to qemu-vm.nix so I can test that with NixOS tests as well)01:38:30
18 Sep 2022
@greaka:greaka.degreaka left the room.11:35:26
19 Sep 2022
@cw:kernelpanic.cafeChinchilla Washington left the room.03:03:21
@lassulus:lassul.uslassulus joined the room.15:43:04
24 Sep 2022
@alexandre:iooss.frAlexandre https://nixos.wiki/wiki/TPM I just started a new wiki page to help users to use their TPM on NixOS
There is still things that I don't understand, I have set security.tpm2.tctiEnvironment.enable=true and have the corresponding environment variables pointing to device,/dev/tpmrm0, but OpenSSH is still trying to init FAPI backend (and fail)
13:21:04
30 Sep 2022
@joerg:thalheim.ioMic92 Alexandre: nice. How do you backup such a key? 11:53:10
@alexandre:iooss.frAlexandre
In reply to @joerg:thalheim.io
Alexandre: nice. How do you backup such a key?
I am still learning the spec, but maybe it is possible to import a key using tpm2-pkcs11 (which would allow a backup). It is clearly one of the question that needs to be answered on the wiki page ><"
11:55:51
2 Oct 2022
@leons:is.currently.onlineLeon
In reply to @alexandre:iooss.fr
https://nixos.wiki/wiki/TPM I just started a new wiki page to help users to use their TPM on NixOS
There is still things that I don't understand, I have set security.tpm2.tctiEnvironment.enable=true and have the corresponding environment variables pointing to device,/dev/tpmrm0, but OpenSSH is still trying to init FAPI backend (and fail)
I think this might be something I've noticed all over the TPM2 domain. It seems that almost every tool chooses its own generic-sounding environment variable to rely on.
19:16:40
5 Oct 2022
@rosariopulella:matrix.orgRosuavio joined the room.19:08:59
6 Oct 2022
@colemickens:matrix.orgcolemickens there's a number of talks in this conf that are related to TPMs, but this one is particularly intriguing to me, maybe of interest to others here: https://www.osfc.io/2022/talks/user-friendly-lightweight-tpm-remote-attestation-over-bluetooth/ 01:43:17
15 Oct 2022
@tinybronca:sibnsk.netunderpantsgnome changed their display name from underpantsgnome to underpantsgnome!.00:39:57
29 Oct 2022
@uep:matrix.orguep joined the room.06:06:19
30 Oct 2022
@madouura:matrix.orgMadoura joined the room.02:01:00
31 Oct 2022
@tinybronca:sibnsk.netunderpantsgnome changed their display name from underpantsgnome! to underpantsgnome.20:29:22
16 Nov 2022
@zuckerberg:neet.spacezuckerberg changed their profile picture.15:53:05
@omlet:matrix.orgomlet joined the room.20:34:18
17 Nov 2022
@myaats:matrix.orgMats joined the room.00:21:50
@elvishjerricco:matrix.orgElvishJerricco Is there a reasonable way to do remote attestation with the TPM? systemd doesn't seem to have anything included, and the tpm2-tools CLI and documentation are... extremely unfriendly and confusing 18:38:12
@omlet:matrix.orgomlet left the room.18:50:04
18 Nov 2022
@grahamc:nixos.org@grahamc:nixos.orghttps://github.com/bloomberg/spire-tpm-plugin14:21:37
@grahamc:nixos.org@grahamc:nixos.orgmight have something interesting for you14:21:50
25 Nov 2022
@tired:fairydust.spacetired joined the room.22:21:48
26 Nov 2022
@js:ukvly.orgJulian Stecklina (Old) joined the room.15:29:05
@js:ukvly.orgJulian Stecklina (Old)Hi 👋. Can someone add this room to the NixOS org to make it easier to find? :)15:29:44

Show newer messages


Back to Room ListRoom Version: 6