!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

180 Members
44 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.org

takeownership does 2 thinsg afaik:

  1. resets the seed which is used for all the root key calculations
  2. sets a password used to reset counters
12:14:06
@grahamc:nixos.org@grahamc:nixos.orgso you can set a policy saying increment a counter on decrypt attempt, and refuse if it goes about 10, then you need the ownership password to reset it12:14:51
@andi:kack.itandi-Ok, so that part is then stored in the NV RAM of the TPM?12:15:35
@grahamc:nixos.org@grahamc:nixos.orgyeah12:15:43
@grahamc:nixos.org@grahamc:nixos.orgyou don't need any special credential to use the roots12:15:55
@grahamc:nixos.org@grahamc:nixos.org
I am still a bit confused by the requirement of different secrets to decrypt one secret.
12:16:49
@andi:kack.itandi-Does the internal seed change the PCR values? I guess it shouldn't...12:16:54
@grahamc:nixos.org@grahamc:nixos.orgI think this is because you're maybe not ever going to decrypt it12:16:56
@grahamc:nixos.org@grahamc:nixos.orgbut maybe you're just using it for attestation 12:17:07
@grahamc:nixos.org@grahamc:nixos.orgI don't think the seed has anything to do with the PCR, yeah12:18:16
@grahamc:nixos.org@grahamc:nixos.orgRedacted or Malformed Event12:19:07
@grahamc:nixos.org@grahamc:nixos.orgah here we are12:20:30
@grahamc:nixos.org@grahamc:nixos.orgyou can get what the TPM calls a "quote" which is the PCRs signed by the TPM, in a way you can trust itis actually the PCRs and not falsified 12:21:03

Show newer messages


Back to Room ListRoom Version: 6