18–20 Sept 2024
Europe/Vienna timezone

Measured Boot, Secure Attestation & co, with systemd

18 Sept 2024, 12:40
20m
"Hall N2" (Austria Center)

"Hall N2"

Austria Center

161
System Boot and Security MC System Boot and Security MC

Speaker

Lennart Poettering

Description

systemd has gained various TPM-related components in the recent past, to make measured boot on generic Linux reality.

In this talk I'd like to shed some light on recent developments in this area, and what comes next. Some of the topics touched will (probably) be:

  • Additional PCRs via nvindexes
  • Measurement logs
  • An API for quotes of system state, and remote attestation
  • Dynamically managed, local PCR policies with systemd-pcrlock
  • Setting the TPM's clock
  • Measuring more resources and events

Primary author

Presentation materials