Re: are you using journalctl FSS consistency checks?

2022-06-08 Thread Matthew Miller
On Wed, Jun 08, 2022 at 12:37:03PM +0200, Zbigniew Jędrzejewski-Szmek wrote: > ** are you using 'journal --setup-keys' and 'journalctl --verify-key=…'? > In no, feel free to ignore this. I tried it back in the day (like, 10 years ago), and concluded that the "just delete logs" hole made it not

are you using journalctl FSS consistency checks?

2022-06-08 Thread Zbigniew Jędrzejewski-Szmek
Hi! ** are you using 'journal --setup-keys' and 'journalctl --verify-key=…'? In no, feel free to ignore this. ** background story: [A very simplified explanation of "Forward Secure Sealing": public-private key pair is generated when setting up a journal, the private key is copied off the device