!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

160 Members
39 Servers

Load older messages


SenderMessageTime
29 Nov 2024
@lassulus:lassul.uslassulus changed their profile picture.18:30:04
1 Dec 2024
@shawn8901:matrix.orgshawn8901 joined the room.17:03:53
8 Dec 2024
@shawn8901:matrix.orgshawn8901 set a profile picture.19:21:16
11 Dec 2024
@baloo_:matrix.orgbalooJust published this PR https://github.com/NixOS/nixpkgs/pull/364379 I'm using this to mock up EK certificate in a TPM. I'd love to get some eyes on it if possible.22:57:12
12 Dec 2024
@numinit:matrix.orgMorgan (@numinit)Very cool01:56:24
@numinit:matrix.orgMorgan (@numinit) I'll give it a review :-) 01:59:26
@baloo_:matrix.orgbaloo Morgan (@numinit): thanks a lot for the review! 04:13:57
@numinit:matrix.orgMorgan (@numinit)No problem, this will be super useful for the nixPKCS test suite 04:14:27
@numinit:matrix.orgMorgan (@numinit)Really appreciate the change! 04:14:34
@baloo_:matrix.orgbalooYeah that makes my test suite a lot more easy to run too04:15:11
@baloo_:matrix.orgbaloomuch easier than having to pull real hardware04:15:25
@numinit:matrix.orgMorgan (@numinit)I was going to add attestation support eventually to https://github.com/numinit/nixpkcs - this is a kick in the pants for me to do it04:15:46
@numinit:matrix.orgMorgan (@numinit) Someone just got step-ca working with it though, which is encouraging 04:16:40
@baloo_:matrix.orgbalooFriends don't let people use pkcs1104:16:49
@numinit:matrix.orgMorgan (@numinit)hah04:16:56
@baloo_:matrix.orgbaloo(I hate pkcs11 dearly)04:17:15
@numinit:matrix.orgMorgan (@numinit) Brutally hard to wrap things with, I do too. Had to do passthrus for it all 04:17:31
@numinit:matrix.orgMorgan (@numinit)This does actually make it easier, though through the brute force of injecting support into OpenSSL04:18:14
@baloo_:matrix.orgbalooyeah, looks like you figured out a bunch of options in a bunch of very useful tools04:19:05
@numinit:matrix.orgMorgan (@numinit) Basically, yeah. 04:19:18
@baloo_:matrix.orgbalooI guess you ended up full of yak hair after doing that04:19:21
@baloo_:matrix.orgbaloo(thanks for doing that)04:19:45
@baloo_:matrix.orgbalooor full of weeds I guess04:19:57
@numinit:matrix.orgMorgan (@numinit)yeah, pretty much - declarative definition of yubikeys is pretty cool at least04:19:58
@numinit:matrix.orgMorgan (@numinit)though I completely understand why wo one supported PKCS11 now - it's a pain in the @$$04:20:50
@baloo_:matrix.orgbaloohave you had the delight to work HSM vendors already?04:20:55
@numinit:matrix.orgMorgan (@numinit)* though I completely understand why no one supported PKCS11 now - it's a pain in the @$$04:20:56
@numinit:matrix.orgMorgan (@numinit) ... yep. 04:21:10
@numinit:matrix.orgMorgan (@numinit)Different tools for everything04:21:21
@baloo_:matrix.orgbaloocondolences 04:21:23

Show newer messages


Back to Room ListRoom Version: 6