!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

192 Members
49 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
18 Jul 2021
@andi:kack.itandi- manveru: have you been using this on unstable with pkcs11 with e.g. OpenSSH? I've had to patch your tpm2-tss derivation to use pkcs11 17:02:29
@manveru:matrix.orgmanveruNot yet, I'm just getting started trying to use tpm :)17:03:36
@manveru:matrix.orgmanveruPretty sure there's no tpm drv from me...17:04:02
@grahamc:nixos.org@grahamc:nixos.org andi-: okay so you CAN specify an index when defining the region, but there are defined allocations https://trustedcomputinggroup.org/wp-content/uploads/RegistryOfReservedTPM2HandlesAndLocalities_v1p1_pub.pdf 20:02:33
@grahamc:nixos.org@grahamc:nixos.org
[nix-shell:~]# tss2 getplatformcertificates
WARNING:fapi:src/tss2-fapi/ifapi_io.c:282:ifapi_io_check_create_dir() Directory /nix/store/cmkbhbf74dzy2kaxsamvkr2pbiqvhx89-tpm2-tss-3.0.3/var/run/tpm2-tss/eventlog/ does not exist, creating 
WARNING:fapi:src/tss2-fapi/ifapi_io.c:282:ifapi_io_check_create_dir() Directory /root//.local/share/tpm2-tss/user/keystore does not exist, creating 
WARNING:fapi:src/tss2-fapi/ifapi_io.c:282:ifapi_io_check_create_dir() Directory /nix/store/cmkbhbf74dzy2kaxsamvkr2pbiqvhx89-tpm2-tss-3.0.3/var/lib/tpm2-tss/system/keystore/policy does not exist, creating 

sigh

20:19:05
@andi:kack.itandi-That is normal :d20:19:18
@andi:kack.itandi-I also get those and can still authenticate my SSH session20:19:30
@andi:kack.itandi-But yeah it is not optimal..20:19:44
@andi:kack.itandi-I hope I'll have some time to read the TPM2.0 spec next week. Been not doing much since Thursday and the weekend was occupied otherwise20:20:31
@grahamc:nixos.org@grahamc:nixos.orgunderstandable20:21:00
@grahamc:nixos.org@grahamc:nixos.org I wonder why getplatformcertificates is suddenly part of tss and not the tpm2 command 20:21:23
@andi:kack.itandi-the developers of tss needed it before they started the tpm2 tool?20:22:09
@grahamc:nixos.org@grahamc:nixos.orghm20:22:21
19 Jul 2021
@manveru:matrix.orgmanverudoes anyonne know if there's some way to turn tpm emulation on for a nixos test?06:23:46
@andi:kack.itandi-The current VM infrastructure doesnt allow that. You have to run an additional daemon 07:13:39

Show newer messages


Back to Room ListRoom Version: 6