| 24 Jan 2022 |
@colemickens:matrix.org | Thanks a bunch Zhaofeng Li , I'll have to spend another weekend day trying to do this the right way then! | 22:47:21 |
| 31 Jan 2022 |
| @bernardo:matrix.parity.io changed their profile picture. | 11:49:42 |
| 2 Feb 2022 |
| @cw:kernelpanic.cafe changed their display name from CoilWinder (novus ordo seclorum) to Chuck Winter. | 08:37:03 |
| 3 Feb 2022 |
| lvkm joined the room. | 08:49:27 |
| lewo joined the room. | 21:47:17 |
| 4 Feb 2022 |
@mic92:nixos.dev | is this any good? https://github.com/whooo/tpm2-ssh-agent | 14:08:18 |
| 15 Feb 2022 |
@stigo:matrix.org | In reply to @mic92:nixos.dev is this any good? https://github.com/whooo/tpm2-ssh-agent I've been using gpg with tpm for ssh for a while now, quite happy with it. Unable to change passphrases for tpm backed keys tho. | 16:02:28 |
@stigo:matrix.org | Was wondering if anyone has had any luck setting up TPM2 with LUKS on NixOS? | 16:03:08 |
@mic92:nixos.dev | I try to keep my system gnupg-free because of bad past experiences. I think andi- was working on that, but don't know the status | 16:04:05 |
@stigo:matrix.org | "happy" and "gpg" are unlikely to be in the same sentence though. | 16:04:08 |
Zhaofeng Li | In reply to @stigo:matrix.org Was wondering if anyone has had any luck setting up TPM2 with LUKS on NixOS? I use clevis and add the decrypt command to my boot.initrd.luks.devices.<name>.preOpenCommands | 16:30:19 |
Zhaofeng Li | I added an option so the decryption process immediately falls back to password if the key file doesn't exist instead of waiting: https://github.com/NixOS/nixpkgs/pull/150196 | 16:31:16 |
Zhaofeng Li | For better TPM+LUKS integration, there was https://github.com/NixOS/nixpkgs/pull/134577 but it was decided that we wanted to wait for systemd in stage-1 for cryptenroll support which is still in limbo at the moment | 16:33:00 |
@stigo:matrix.org | In reply to @zhaofeng:zhaofeng.li I use clevis and add the decrypt command to my boot.initrd.luks.devices.<name>.preOpenCommands Thx for the info! Yeah, I'll be patient and wait for systemd-cryptenroll stuffs to be ready | 16:41:58 |
@stigo:matrix.org | Just to mention about gpg. Some of the things that work well with it are ssh and encryption/decryption (vith epa in emacs, and tomb, for instance), and has a nice tpm2 integration. Signature verification, trust models, sks, email, and all that is a different story though. Imho. | 16:54:31 |
@stigo:matrix.org | * Just to mention about gpg. Some of the things that work well with it are ssh and encryption/decryption (vith epa in emacs, tomb, and pass, for instance), and has a nice tpm2 integration. Signature verification, trust models, sks, email, and all that is a different story though. Imho. | 16:57:03 |
| * @colemickens:matrix.org contemplates the meaning of "work well" vs "works, after internalizing countless pitfalls and nearly encoding gpg quirks as muscle memory" | 20:14:56 |
@stigo:matrix.org | In reply to * @colemickens:matrix.org contemplates the meaning of "work well" vs "works, after internalizing countless pitfalls and nearly encoding gpg quirks as muscle memory" Yeah, there is for sure a lot of that. s/work well/is useful/ would be more accurate. | 20:22:49 |