!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

172 Members
49 Servers

Load older messages


SenderMessageTime
12 Dec 2024
@numinit:matrix.orgMorgan (@numinit)I'm surprised PKCS#11 can even generate keys04:21:48
@numinit:matrix.orgMorgan (@numinit)support apparently has been recently improving in general with AWS and Google's cloud HSMs04:22:19
@baloo_:matrix.orgbalooha yeah, the easy ones :D04:22:36
@numinit:matrix.orgMorgan (@numinit)when the standard says something is optional, no one implements it04:22:44
@baloo_:matrix.orgbaloowait until you use the thales or entrust ones :D04:23:02
@baloo_:matrix.orgbaloo(don't use entrust)04:23:09
@numinit:matrix.orgMorgan (@numinit)lol, qualcomm low level bringup has been my recent 😢04:23:27
@baloo_:matrix.orgbalooqualcomm makes HSMs?04:23:42
@numinit:matrix.orgMorgan (@numinit)not really, trusted environments on chip that are TPM "compatible" 04:24:08
@baloo_:matrix.orgbalooha yeah those04:24:23
@numinit:matrix.orgMorgan (@numinit)with as loose air quotes as Qualcomm deserves 04:24:29
@baloo_:matrix.orgbalooThis is next year project I think04:25:08
@baloo_:matrix.orgbaloolooking forward to that ><04:25:13
@numinit:matrix.orgMorgan (@numinit)that and plenty of Android (OEM) key attestation, which uses them and also completely stretches the definition of key attestation in a million ways 04:26:28
@numinit:matrix.orgMorgan (@numinit) asn.1 for days... 04:27:09
@numinit:matrix.orgMorgan (@numinit)fun fact:04:53:25
@numinit:matrix.orgMorgan (@numinit)PKCS#11 was created by OASIS, the same creators of standards as well designed and respected as.... SAML04:53:57
@numinit:matrix.orgMorgan (@numinit) 😬But at least they somewhat redeemed themselves with virtio. 04:54:25
14 Dec 2024
@netpleb:matrix.orgnetpleb joined the room.23:24:44
@netpleb:matrix.orgnetplebIs it possible for me to supply the seeds for my TPM rather than have the TPM generate them?23:31:15
@netpleb:matrix.orgnetpleb * Is it possible for me to supply the seeds to my TPM rather than have the TPM generate them?23:31:29
@netpleb:matrix.orgnetpleb * Is it possible for me to supply the endorsement and platform seeds to my TPM rather than have the TPM generate them?23:36:25
16 Dec 2024
@netpleb:matrix.orgnetpleb attempting to answer my own question here: as far as I can tell this is probably possible for a virtual/emulated TPM but is likely not straightforward. Still not sure about physical TPMs 20:48:09
22 Dec 2024
@allrealmsoflife:matrix.orgallrealmsoflife joined the room.20:27:05
24 Dec 2024
@karlthane:matrix.orgkarlthane joined the room.13:57:17
@karlthane:matrix.orgkarlthane left the room.14:03:13
@karlthane:matrix.orgkarlthane joined the room.14:09:52
25 Dec 2024
@cathal_mullan:matrix.orgCathal joined the room.14:38:33
26 Dec 2024
@10leej:matrix.org@10leej:matrix.org joined the room.01:41:10
@10leej:matrix.org@10leej:matrix.org left the room.01:41:56

Show newer messages


Back to Room ListRoom Version: 6