!agkXCfUrgbadYlQXRj:kack.it

NixOS + TPMs

174 Members
43 Servers

Load older messages


SenderMessageTime
11 Aug 2021
@grahamc:nixos.org@grahamc:nixos.orgI'd love to see development in that area, it'd be a bit tricky to know you're supposed to have access to the signing key15:44:08
@mic92:nixos.dev@mic92:nixos.devI just stumbled over this features for the first time when modifying some runc hypervisor.15:48:29
@andi:kack.itandi- we could have a disallowedRequisites = [ kernel.signingKey ]; as very minimal "safety" against having the key world readable on the system (by accident). That is obviously not a silver bullet. Everyone that can build software against the systems nixpkgs checkout could generate properly signed modules and given that it would have to be deterministic you could probably just generate the key "offline" on another box.. 15:52:46
@andi:kack.itandi-What exactly are we gaining again? :D15:52:55
@mic92:nixos.dev@mic92:nixos.devSo would need an activation phase that signs all keys afterwards?16:10:35
13 Aug 2021
@grahamc:nixos.org@grahamc:nixos.orgthe work I'm doing around secureboot support is based on a more involved bootloader "install" step which could support signing modules19:47:39
18 Aug 2021
@mic92:nixos.dev@mic92:nixos.devhttps://github.com/NixOS/nixpkgs/pull/13457705:30:59
@grahamc:nixos.org@grahamc:nixos.org
     tpm2_unseal -c ${dev.tpm2KeyFile.persistentObject} -p ${dev.tpm2KeyFile.authString} > /crypt-ramfs/tpm/unsealed
14:47:23
@grahamc:nixos.org@grahamc:nixos.orgI'm thinking this should be starting an auth session (I think that is the right term) and using the session key for subsequent calls so that the channel with the TPM is all encrypted14:48:23
@grahamc:nixos.org@grahamc:nixos.orgis tpm2_startauthsession the command which does that?14:48:52
@roosemberth:orbstheorem.ch@roosemberth:orbstheorem.ch joined the room.18:47:17
29 Aug 2021
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️ joined the room.09:45:57
31 Aug 2021
@florian:web3.foundation@florian:web3.foundation changed their display name from Florian | W3F to Florian | W3F - OoO.08:11:03
2 Sep 2021
@tnias:stratum0.orgtnias joined the room.21:50:46
4 Sep 2021
@0x4a6f:matrix.org[0x4A6F] joined the room.09:55:44
9 Sep 2021
@sugi:matrix.besaid.de@sugi:matrix.besaid.de joined the room.22:35:18
13 Sep 2021
@florian:web3.foundation@florian:web3.foundation changed their display name from Florian | W3F - OoO to Florian | W3F - OoO Mon/Tue.11:56:00
17 Sep 2021
@cleverca22:matrix.org@cleverca22:matrix.org joined the room.06:04:06
18 Sep 2021
@cw:kernelpanic.cafe@cw:kernelpanic.cafe joined the room.20:51:53
20 Sep 2021
@cw:kernelpanic.cafe@cw:kernelpanic.cafe changed their display name from CornWallace to Rev. CornWallace III.06:45:31
@cw:kernelpanic.cafe@cw:kernelpanic.cafe changed their display name from Rev. CornWallace III to Rev. CornWallace III (tzu/tzi).15:22:30
@cw:kernelpanic.cafe@cw:kernelpanic.cafe changed their display name from Rev. CornWallace III (tzu/tzi) to Rev. CornWallace III (sun/tzu).15:24:51
21 Sep 2021
@schnecfk:ruhr-uni-bochum.de@schnecfk:ruhr-uni-bochum.de joined the room.13:20:49
23 Sep 2021
@mic92:nixos.dev@mic92:nixos.devI always enjoy lennart's articles: http://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html15:43:40
@colemickens:matrix.org@colemickens:matrix.orgread that, came here to see what folks are doing in this space w/ nixos22:16:31
@colemickens:matrix.org@colemickens:matrix.orgcurious how much you're redo-ing the bootloader install process graham, I've been increasingly intererested in seeing cross-arch NixOS installs be easier. It seems like if they were written correctly, there could be a platform agnostic install script that would be runnable from any "build" platform.22:17:53
@colemickens:matrix.org@colemickens:matrix.org * curious how much you're redo-ing the bootloader install process Graham -- I've been increasingly interested in seeing cross-arch NixOS installs be easier. It seems like if they were written correctly, there could be a platform agnostic install script that would be runnable from any "build" platform.22:18:08
24 Sep 2021
@cw:kernelpanic.cafe@cw:kernelpanic.cafe changed their display name from Rev. CornWallace III (sun/tzu) to Rev. CornWallace III (novus ordo seclorum).01:00:50
1 Oct 2021
@colemickens:matrix.org@colemickens:matrix.orgLeonnart's issues on the cryptsetup tracker are interesting, a bit tangential but somewhat related to this room: https://gitlab.com/cryptsetup/cryptsetup/-/issues/67420:03:59
@colemickens:matrix.org@colemickens:matrix.orgincluding the linked one about reusing LUKS ux for dm-integrity20:04:13

Show newer messages


Back to Room ListRoom Version: 6