!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

174 Members
46 Servers

Load older messages


SenderMessageTime
3 May 2022
@v0id:nltrix.netv0|dthis brough me here.07:32:07
@v0id:nltrix.netv0|d * this brought me here.07:32:20
@zhaofeng:zhaofeng.liZhaofeng LiIf you have a TPM, authenticating the boot chain is actually pretty easy. You can either use tpm2-attest or have it decrypt some secret with clevis.07:35:48
@v0id:nltrix.netv0|dare there any pages on wiki regarding grub/tpm/initrd?07:36:47
@ar:hackerspace.plar joined the room.08:29:44
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @v0id:nltrix.net
are there any pages on wiki regarding grub/tpm/initrd?
Don't think there is one at the moment
22:45:25
4 May 2022
@bernardo:matrix.parity.iobernardo changed their display name from bernardo to bernardo ooo (sick).11:07:57
5 May 2022
@anthr76:mozilla.organthr76 joined the room.02:23:14
@bernardo:matrix.parity.iobernardo changed their display name from bernardo ooo (sick) to bernardo.12:38:32
7 May 2022
@jakobu5:hellothere.atJakob joined the room.13:00:52
9 May 2022
@kayla.fire:matrix.orgkayla (she/they) joined the room.10:57:32
14 May 2022
@florian:web3.foundationFlorian | W3F changed their display name from Florian | W3F to Florian | OoO -> 29.5..11:56:58
21 May 2022
@leons:is.currently.onlineLeon joined the room.20:33:43
@martin:mawalabs.deMartin joined the room.21:01:36
22 May 2022
@emantor:stratum0.orgEmantor joined the room.08:52:04
23 May 2022
@florian:wolkenplanet.deFlorian joined the room.14:19:22
24 May 2022
@mixis:bau-ha.usmixis joined the room.16:28:49
@bernardo:matrix.parity.iobernardo left the room.21:00:22
25 May 2022
@mic92:nixos.devMic92 (Old)Not sure what the best channel for this question is, but do you have some automation/recommndation on how to bootstrap vault access on new machines? 10:41:04
27 May 2022
@grahamc:nixos.org@grahamc:nixos.orghardware?13:23:17
@grahamc:nixos.org@grahamc:nixos.org * bare metal hardware that you own?13:23:23
@grahamc:nixos.org@grahamc:nixos.org Mic92: ^ 13:23:49
@grahamc:nixos.org@grahamc:nixos.orgfor people I push them through logging in with google apps, for bare metal hardware I was working on this but didn't end up needing it: https://github.com/grahamc/vault-credential-yubikey13:24:45
@grahamc:nixos.org@grahamc:nixos.org(but it completely works)13:24:56
@mic92:nixos.devMic92 (Old)
In reply to @grahamc:nixos.org
Mic92: ^
Let's say something cloud-vendor neutral. I need to be able to migrate if possible.
13:25:26
@grahamc:nixos.org@grahamc:nixos.orgI'd use whatever auto auth method you can built-in to vault, trying to remain vendor neutral on that is (imho) missing out on a lot of really good security engineering13:26:34
@grahamc:nixos.org@grahamc:nixos.orgie: AWS, Azure, GCP, etc. all have built-in automatic authentication mechanisms that I'd take advantage of13:27:13
@mic92:nixos.devMic92 (Old)Do you usually deploy vault enterprise?13:27:24
@grahamc:nixos.org@grahamc:nixos.orgno13:27:36
@grahamc:nixos.org@grahamc:nixos.orgI don't have that kind of budget 😓13:27:53

Show newer messages


Back to Room ListRoom Version: 6