[systemd-devel] Measured systemd-sysext

2024-05-24 Thread Dimitris Karakasilis
Hi, we (at kairos.io) are trying to understand how systemd-sysext extensions can also be made tamper-proof by being measured in a system that boots in UKI mode. Specifically, when Kairos boots in "UKI mode", the whole operating system is signed and measurements in PCRs 7 and 11 are gating th

Re: [systemd-devel] Measured systemd-sysext

2024-05-24 Thread Lennart Poettering
On Fr, 24.05.24 17:39, Dimitris Karakasilis (dimit...@karakasilis.me) wrote: > we (at kairos.io) are trying to understand how systemd-sysext > extensions can Hmm, I thought kairos wasn't so fond of systemd? > also be made tamper-proof by being measured in a system that boots in UKI > mode. It's

Re: [systemd-devel] Measured systemd-sysext

2024-05-27 Thread Dimitris Karakasilis
On 24/5/24 18:44, Lennart Poettering wrote: On Fr, 24.05.24 17:39, Dimitris Karakasilis (dimit...@karakasilis.me) wrote: we (at kairos.io) are trying to understand how systemd-sysext extensions can Hmm, I thought kairos wasn't so fond of systemd? Why would you think that? Kairos is distro-agno