Re: [systemd-devel] Usage of PCR[7]

2023-06-06 Thread Andrei Borzenkov
On Tue, Jun 6, 2023 at 8:20 AM Mantas Mikulėnas wrote: > > On Mon, Jun 5, 2023 at 11:38 PM Adrian Vovk wrote: >> >> >> 2. The alternative approach involves pre-calculating PCR[7] on the >> client if we're updating DBX or Shim. Here's how I envision this >> going: >> - We read the TPM log (which

Re: [systemd-devel] Usage of PCR[7]

2023-06-05 Thread Mantas Mikulėnas
On Mon, Jun 5, 2023 at 11:38 PM Adrian Vovk wrote: > > 2. The alternative approach involves pre-calculating PCR[7] on the > client if we're updating DBX or Shim. Here's how I envision this > going: > - We read the TPM log (which we can trust because we're currently > booted to system verified

[systemd-devel] Usage of PCR[7]

2023-06-05 Thread Adrian Vovk
Hello all, I'm working on a general-purpose distro modeled after the proposal made in "Fitting Everything Together". I'm planning to, by default, seal the data partition's encryption with the following PCRs: - PCR[7]: If secure boot gets turned off, or keys get replaced -> fail decryption -