Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Seal disk decryption key to PCR 13 #2700

Merged
merged 1 commit into from
Jul 5, 2022

Conversation

mikem-zed
Copy link
Contributor

PCR 13 is used by GRUB to measure rootfs and config partitions

It is safe to mere this even though we do not have GRUB PR yet. all PCRs have their default values

@eriknordmark eriknordmark changed the title Seal disk decription key to PCR 13 Seal disk decryption key to PCR 13 Jul 4, 2022
Copy link
Contributor

@eriknordmark eriknordmark left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would good to explore what this does during EVE update and fallback.
Hmm - maybe that is a non-issue since we always need to do the remote attestation as we move from one EVE version to another?

PCR 13 is used by GRUB to measure rootfs and config partitions

Signed-off-by: Mikhail Malyshev <mikem@zededa.com>
@mikem-zed mikem-zed force-pushed the mikem/seal-key-to-fs-pcr branch from 8e41caf to acd0eac Compare July 4, 2022 17:01
@eriknordmark
Copy link
Contributor

FWIW I defined a git alias (which I called ci) which does commit -S to avoid missing the DCO

Copy link
Contributor

@eriknordmark eriknordmark left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eriknordmark eriknordmark merged commit aa3501d into lf-edge:master Jul 5, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants