!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

172 Members
42 Servers

Load older messages


SenderMessageTime
9 Mar 2023
@redstone-menace:matrix.orgRedstone joined the room.05:00:39
@pedrohlc:mozilla.orgpedrohlc changed their profile picture.13:30:25
14 Mar 2023
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them) to ckie (they/them; heavily limited keyboard usage, dictation or voice only).01:10:19
15 Mar 2023
@Cornu:matrix.orgcornu joined the room.21:14:25
19 Mar 2023
@quasineutral:matrix.orgquasineutral joined the room.11:44:55
23 Mar 2023
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them; heavily limited keyboard usage, dictation or voice only) to ckie (they/them; limited keyboard usage, voice preferred).02:05:13
2 Apr 2023
@aktaboot:tchncs.deaktaboot left the room.17:13:08
16 Apr 2023
@ianluo001:matrix.orgian luo joined the room.02:27:17
17 Apr 2023
@genericnerdyusername:matrix.orgGenericNerdyUsername joined the room.22:56:18
28 Apr 2023
@raitobezarius:matrix.orgraitobezarius ElvishJerricco: so you have TPM2 unlock with systemd-measure for PCRs? 13:06:47
@elvishjerricco:matrix.orgElvishJerricco raitobezarius: Yea, using https://github.com/DeterminateSystems/bootspec-secureboot/pull/240 13:10:49
@raitobezarius:matrix.orgraitobezariusalright I might port this to lanzaboote13:17:10
@elvishjerricco:matrix.orgElvishJerriccoTwo things to note13:18:54
@elvishjerricco:matrix.orgElvishJerricco raitobezarius: 1) The systemd-pcrphase units are conditional on an efi variable set by systemd-stub. 2) it's overly convoluted; you don't have to use systemd-stub and systemd-measure and all that garbage because you can actually just use the systemd-pcrphase executable and just extend PCR 11 without all the PE section nonsense 13:21:33
@raitobezarius:matrix.orgraitobezariusI know about 1)13:21:47
@raitobezarius:matrix.orgraitobezariusI didn't know about 2)13:22:03
@raitobezarius:matrix.orgraitobezariuslanzaboote stub is to become the systemd-stub nextgen :P13:22:34
@raitobezarius:matrix.orgraitobezariusSo 1) is not a problem13:22:37
@elvishjerricco:matrix.orgElvishJerriccoYea the reason to bind things against the section contents of a UKI would be as a poor man's secure boot13:22:58
@elvishjerricco:matrix.orgElvishJerriccoso if you have actual secure boot and bind to pcr 7, it's not important13:23:09
@elvishjerricco:matrix.orgElvishJerriccoand at that point pcrphase is only serving the purpose of phase control, so that the TPM only unlocks things during the appropriate boot phase13:23:36
@elvishjerricco:matrix.orgElvishJerriccoSo I guess you still need something like systemd-measure, except if you don't care about measuring UKI sections you could leave those out and just measure the phase path13:27:07
@elvishjerricco:matrix.orgElvishJerriccowhich I don't think is a mode that systemd-measure will do13:27:30
@baloo_:matrix.orgbalooauthenticode PE hash thing is just a matter of filtering out the checksum and the signature section from the hash17:33:19
@baloo_:matrix.orgbalooother than that, it's a plain hash of the file.17:33:34
@baloo_:matrix.orgbaloo( https://github.com/m4b/goblin/pull/362/files )17:34:54
8 May 2023
@pedrohlc:mozilla.orgpedrohlc changed their profile picture.13:33:33
12 May 2023
@samueldr:matrix.orgsamueldr changed their profile picture.02:29:46
@lassulus:lassul.uslassulus changed their profile picture.10:12:06
@lassulus:lassul.uslassulus changed their profile picture.13:39:13

Show newer messages


Back to Room ListRoom Version: 6