Received: by 2002:ab2:6a05:0:b0:1f8:1780:a4ed with SMTP id w5csp2726873lqo; Tue, 14 May 2024 07:31:01 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCX2iA7wAQOG+EgJ+D6l8Pru1/cBuFuA7Fg3UjxrQJBKRAY7LANj9CD4Rtr1yQl+iKaU1BriewjJKSWmdnM1KsXYuGXQcwxG7egTwr5iLg== X-Google-Smtp-Source: AGHT+IFW/CRh5JoUbVosmGEivFPIcH/Z9emAJ0qDHrtQsbmvzHgYKtjAXnQjIKKyNV4vLLtQx9Yi X-Received: by 2002:a17:906:f34a:b0:a5a:86e8:420b with SMTP id a640c23a62f3a-a5a86e842fdmr115452166b.48.1715697061018; Tue, 14 May 2024 07:31:01 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1715697061; cv=pass; d=google.com; s=arc-20160816; b=HmVdBkCiiCJyiMiXgK4Q5CcviM9zS0Cjp/p1nnA2P9+2w7Yb1Wq1p+VWa5A6WbBAaD JTWqNSFSuOtzj/i7ctKPuCNPSHTVsyFU8FCuDAuY52/qz1j6Xc7iUg/CEVpfg0vxmd8r /EYb/Flcu7Fi9zrTQbs824MaGMiDnpPyy8Ii/SR3RxmhtD3QvQmbWQIjPup5ZpRi7Buv jpfTCclbuYwK71JPQw7juuGG6iNmlXcFtamH5rsT8ARNPRW9pgMGs6fLlroRBnt+HILK uzU9avNj3J6CalWdQ96Llh4Gr9GwRVQH8cFaCzWnhqimpXSX1XpL/G2IB84mXLBqVfQ/ cwiQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:dkim-signature; bh=VdX5lbfGhRPzlFouLvem5asYCeRxM5H3J+H/7gd69QA=; fh=/UGr5+ygLQ9CWmeXaQYl8eELK1QldmOmqUeu4IwEPZg=; b=Gd9TXkUWaqjfy+af/fHRIPMwqNMdxciC2HfMQyHjX2Ds4Rzuq4sIFxNtJqixDvMAHX LgcQA8pHtFRxMRWFCVu8fRultUdnyperLPtTQlR8wRlFWRIMRfWwUFTPnpvM7rEtIi30 DFbjpb9nDKAYorITbHwbaJRYSqJmU5kE7USQwZnrbIlJ//ulxJnRFAZF6Uds6RY1FySe pYPNxZZkGokPrD4OHD4kC5x0bRww8TKWunlRaqvOfwW+otJ6GlWEECXzo3qknScibyig 8vZqRxUPgDlwxm/ZkXdYMIYYT4PapsuqDp2zyy+6yy9h+HGckpjU5BJDCZJ2Jv/a8Ped BRuA==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=vRS60n9W; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-178808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-178808-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id a640c23a62f3a-a5a3e2803e1si445885466b.220.2024.05.14.07.31.00 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 May 2024 07:31:00 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-178808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=vRS60n9W; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-178808-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-178808-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id BC5AB1F24AA0 for ; Tue, 14 May 2024 14:31:00 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 009F4154441; Tue, 14 May 2024 14:30:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="vRS60n9W" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E08C15383F; Tue, 14 May 2024 14:30:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715697056; cv=none; b=qWeyKi5RCcTQfaIIuFzkJiq/BfWRQV7oxZidEcUJyLjG15e6EiuJjHoeRJ0hjQNiXU150sbv/wqEkBetPT/6IRwqDfP2smH2JAxOHiiOOMRBSmqmyN4FpQNAXVuFCCrMRs08q6vRlFp+I/HpxsE7QRhj/I31pTZq3nu55xQq2MM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715697056; c=relaxed/simple; bh=2eqOscpDd11AOzITS2akWXa2ETFPtKZfiGkX9/iKc4w=; h=Mime-Version:Content-Type:Date:Message-Id:From:To:Cc:Subject: References:In-Reply-To; b=QShJjwcSdpcfz0VskcA5t0qjMEpUe3nogr4UI65nqZgRgk61dMrisOBF4BDY2LeceXLUQm5QZlOCS4jv6Ac3GPQlqxCEi0WsCwGjJ8oW23aV50X0bhNi1maMDbyVBKzv5app5RSAHUcVHr0od8l/MeWGAAkgOdc2aFarx2u2SCY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=vRS60n9W; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 36BC4C2BD10; Tue, 14 May 2024 14:30:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1715697055; bh=2eqOscpDd11AOzITS2akWXa2ETFPtKZfiGkX9/iKc4w=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=vRS60n9WmS35lU2eQ7883wrPh9NkXFD8fCezaOoEJBIrzjjpx6wDdkY5fdlSeiBhw +PSIaYsbA9hxtq0z0oWm9Vk8Gu19kvGNmUcljyPnU/GSlIyjNtYmBPiKrnRiku38TU ggviF4ejnlB0Kj9/dXVcQaVv7OxB2TOPyt6GkHgeGCq2APC6VkB2jBNc1LlIy/csh2 xePvZB/6yfpTW4tWa0AEJJp3k/QNT373NK2oJIwhpemZ14IiUKDpaZYn1YWE3rYgrY 10Kobq2qgkvyQxE9tYp1eGWs+cDkl0y8Rj4QWLYIopRa2nuwjjvn9m99z/qGd6MIBe 4uEW+rPmagsyg== Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Tue, 14 May 2024 17:30:51 +0300 Message-Id: From: "Jarkko Sakkinen" To: "Jarkko Sakkinen" , "Ignat Korchagin" Cc: "James Bottomley" , "Mimi Zohar" , "David Howells" , "Paul Moore" , "James Morris" , , , , , Subject: Re: [RFC PATCH 0/2] TPM derived keys X-Mailer: aerc 0.17.0 References: <20240503221634.44274-1-ignat@cloudflare.com> In-Reply-To: On Tue May 14, 2024 at 5:00 PM EEST, Jarkko Sakkinen wrote: > On Tue May 14, 2024 at 4:11 PM EEST, Ignat Korchagin wrote: > > For example, a cheap NAS box with no internal storage (disks connected > > externally via USB). We want: > > * disks to be encrypted and decryptable only by this NAS box > > So how this differs from LUKS2 style, which also systemd supports where > the encryption key is anchored to PCR's? If I took hard drive out of my > Linux box, I could not decrypt it in another machine because of this. Maybe you could replace the real LUKS2 header with a dummy LUKS2 header, which would need to be able the describe "do not use this" and e.g. SHA256 of the actual header. And then treat the looked up header as the header when the drive is mounted. LUKS2 would also need to be able to have pre-defined (e.g. kernel command-line or bootconfig) small internal storage, which would be also encrypted with TPM's PRCs containing an array of LUKS2 header and then look up that with SHA256 as the key. Without knowing LUKS2 implementation to me these do not sound reaching the impossible engineer problems so maybe this would be worth of investigating... BR, Jarkko