What is Nostr?
Lennart Poettering /
npub1rk2…zenj
2024-10-31 21:06:46
in reply to nevent1q…el4z

Lennart Poettering on Nostr: If you ask me, it's a fundamental requirement for any modern Linux-based OS to ...

If you ask me, it's a fundamental requirement for any modern Linux-based OS to provide boot time integrity and as baseline provide unattended disk encryption bound to it. To make this happen, we added two essential TPM policy concepts to systemd-cryptenroll/systemd-cryptsetup:

1. Signed TPM PCR policies allow locking a disk to a public signing key of an OS vendor, ensuring that disks can only be unlocked if an OS signed by said vendor is booted.
Author Public Key
npub1rk2uxtv6nk262nucavh259t085a8rhzfaj3vjc9jhzvkyav0rnqqxqzenj