!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

190 Members
50 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 Jul 2021
@grahamc:nixos.org@grahamc:nixos.orgyeah12:13:00
@andi:kack.itandi-So, why that take ownership stuff then?12:13:12
@grahamc:nixos.org@grahamc:nixos.orgyou can create a hierarchy of keys which reveal different amounts of data12:13:20
@andi:kack.itandi-Shouldn't I rather specify the root somehow?12:13:21
@grahamc:nixos.org@grahamc:nixos.orgah12:13:35
@andi:kack.itandi-and the root is also the part that takes the two passwords?12:13:37
@grahamc:nixos.org@grahamc:nixos.orgah, no12:13:43
@grahamc:nixos.org@grahamc:nixos.orgheh12:13:45
@grahamc:nixos.org@grahamc:nixos.org

takeownership does 2 thinsg afaik:

  1. resets the seed which is used for all the root key calculations
  2. sets a password used to reset counters
12:14:06
@grahamc:nixos.org@grahamc:nixos.orgso you can set a policy saying increment a counter on decrypt attempt, and refuse if it goes about 10, then you need the ownership password to reset it12:14:51
@andi:kack.itandi-Ok, so that part is then stored in the NV RAM of the TPM?12:15:35
@grahamc:nixos.org@grahamc:nixos.orgyeah12:15:43
@grahamc:nixos.org@grahamc:nixos.orgyou don't need any special credential to use the roots12:15:55

Show newer messages


Back to Room ListRoom Version: 6