Received: by 10.223.185.116 with SMTP id b49csp1139405wrg; Wed, 14 Feb 2018 12:13:56 -0800 (PST) X-Google-Smtp-Source: AH8x22784ttC6v4bmTcP/RFCdSYL4FMSKW27SJG4kB88jvglqtiEcYS9frqxfJE8YG5ycU+Wm7oO X-Received: by 10.98.2.6 with SMTP id 6mr220590pfc.237.1518639235955; Wed, 14 Feb 2018 12:13:55 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1518639235; cv=none; d=google.com; s=arc-20160816; b=LSBVZoBFzKrvbzW1Lyrv1TxaKbjUVWL+4M0Oz/phuLkL6SGwjPFj8D0TeRWPUB04Ao wYTqvL1whUkWVH1tmqTDsnkDdLNkhYhDfQsPSU2mkRcYBAsUJqTlbtEqANVszwDUsuqs GqJJqHdrSItRODB08db0KOKGc/+mtwOwYLiiSbsCDT+QV1mp4qCrrhp7zYGLWaa3ZtEu b4N17hcElr5BbBKBcbUUb9p5sMILxMQDddZWMXvSmPfeSDlAlGX4pNjuDeXLJwibcKdN yF98N/aQcQHT6OJ9e7Nf6ZM7ASUiQCEZDswKyHuEVGbHAgD4tAh07zvrPAJPU972t/nf QKlQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:date:cc:to:from:subject:message-id :dkim-signature:arc-authentication-results; bh=3cYkofAauKSlQY2kCDm9+bNq0iApZHZOSfzwSiCuHJ4=; b=e8EuJ1vCtRk/R3FfRCG2k77ov6TrbFmAE1OFUMKIrxaBp5iZk0aRsGnaBNBcPiC97L 9XBAzjMX5mmlk2kn6w3GYUvZjynDlnDRb0R1BXAgCs5TnGsQrxu3plzljivKKIeL830B K/e+lLpRSEBsyJUVUBKRHcHqIUYjAhUxueUKapOBXO511GG172WdhP1iVziFqPa04L4A ucp7hmEWhdTUqOMzjMM9Z9SCbfUjXFLfaINGKHOuBEtt69mx7YGwwa+Y7UJss2MhSWOm RxnEU9syGxo71mqaYoOHzk6i9ZLMeVtpYs43mAL5RSzJPN4aweLM3A3zHs08Qze2rFZc i86g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@profitbricks-com.20150623.gappssmtp.com header.s=20150623 header.b=rfP4MT2U; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e16si1567914pgv.581.2018.02.14.12.13.40; Wed, 14 Feb 2018 12:13:55 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@profitbricks-com.20150623.gappssmtp.com header.s=20150623 header.b=rfP4MT2U; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1162636AbeBNTGB (ORCPT + 99 others); Wed, 14 Feb 2018 14:06:01 -0500 Received: from mail-wm0-f43.google.com ([74.125.82.43]:55572 "EHLO mail-wm0-f43.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1162470AbeBNTF7 (ORCPT ); Wed, 14 Feb 2018 14:05:59 -0500 Received: by mail-wm0-f43.google.com with SMTP id a84so13373249wmi.5 for ; Wed, 14 Feb 2018 11:05:59 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=profitbricks-com.20150623.gappssmtp.com; s=20150623; h=message-id:subject:from:to:cc:date:in-reply-to:references :mime-version:content-transfer-encoding; bh=3cYkofAauKSlQY2kCDm9+bNq0iApZHZOSfzwSiCuHJ4=; b=rfP4MT2UO+n6H3qftIrzFEYrNH0gpiEP203KxcR/xIWidO3735YTPqxtC1BWAZ8+UH GgY/UzggpHkitFaT+It3hoBWoPsDXKmgDB0O3taVpYwgZwbDABr3EFfPG3SGjSx/J9BW CLVAdh4co3hOpQ/xprvU6+ouJXqI0Y8RNTCss6nxQP5fFrFuy/GWCdxqlEG+9kpQfDmO UPignSdfVzEa5u4iMTDgUIsx5gJLB4ppPQ0FqdeenRFXd5SEPRkFC804EG11orygNmLc zuKHkJBsOvS75WXHwEE8zCG5OZ9CVT49VaI0HhSDbjXwWld4DEogcY3ED0CjnTi0Ik7h di8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:message-id:subject:from:to:cc:date:in-reply-to :references:mime-version:content-transfer-encoding; bh=3cYkofAauKSlQY2kCDm9+bNq0iApZHZOSfzwSiCuHJ4=; b=hS/3ICK/k8/vzgex23F5pEbf+K4TjFX4f20+02b/hmZM7bHwQvxA6+RYJm0qwomzJZ 2aAmtd8VNVTllwfbv3iU3bRbdcSkZv15xB5Zh+eZqQLnFjJIS9i3Kh1jbj21xU4sdwf1 fW2iYIJroemBV3gSROQAJ71rKevqqTTMFszrubf91UGZQ98X6PKoOMaUUeRwcpm5ZFWR OILwulMMueDlZN0bouiDiJSedSxBwnRDiZClQBPkSCFDYQex/zuvpYXZzmSPGfzBYRVo GvfUPpWPJNlezuAybhX4T9vAmfjrLAK/vSNlWERh4TVmboUzkoKjKZa0jEdFSLtvYLrZ s+wA== X-Gm-Message-State: APf1xPCEwT9qO6QULPpY9+5hvLsTGc7zH4vMKUVkcO3Pwkh4aZ4iompl +sRX4LVV+UQ8C6ZLcUTrhHMgUydhSh0= X-Received: by 10.28.136.139 with SMTP id k133mr81073wmd.11.1518635158740; Wed, 14 Feb 2018 11:05:58 -0800 (PST) Received: from konstrukt ([62.217.45.26]) by smtp.googlemail.com with ESMTPSA id z1sm13946193wre.25.2018.02.14.11.05.57 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Wed, 14 Feb 2018 11:05:57 -0800 (PST) Message-ID: <1518635157.4749.50.camel@profitbricks.com> Subject: Re: Read-protected UEFI variables From: Benjamin Drung To: =?ISO-8859-1?Q?M=F4she?= van der Sterre Cc: Ard Biesheuvel , linux-efi@vger.kernel.org, Linux Kernel Mailing List Date: Wed, 14 Feb 2018 20:05:57 +0100 In-Reply-To: References: <1518612748.4749.29.camel@profitbricks.com> <1518614486.4749.33.camel@profitbricks.com> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.26.1-1 Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Am Mittwoch, den 14.02.2018, 19:18 +0100 schrieb Môshe van der Sterre: > On 02/14/2018 02:21 PM, Benjamin Drung wrote: > > If the UEFI is as secure as storing an unencrypted file on a hard > > drive, I am satisfied. Or do you have a better idea where to store > > the > > SSH keys for a diskless system that boots via network? > > I assume it would be best to use TPM for this (if your systems have > TPM chips), it is designed for use-cases like this. Searching for > "tpm ssh keys" gives a decent amount of results. Mostly targeted at > user keys instead of server keys, so this might need some tinkering > to get working. I check our systems. They just have TPM headers, but no TPM chips according to the user manual. The directory /sys/class/tpm/ is either empty or not existing. Adding TPM chips to all servers is no too expensive (to much man power required). So sadly, this is no option for us. -- Benjamin Drung System Developer Debian & Ubuntu Developer ProfitBricks GmbH Greifswalder Str. 207 D - 10405 Berlin Email: benjamin.drung@profitbricks.com URL: https://www.profitbricks.de Sitz der Gesellschaft: Berlin Registergericht: Amtsgericht Charlottenburg, HRB 125506 B Geschäftsführer: Achim Weiss, Matthias Steinberg