|
[isar-cip-core][PATCH v2] initramfs-crypt-hook: Add clevis for buster and bullseye
From: Quirin Gylstorff <quirin.gylstorff@...> This will remove the requirement to use bullseye backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Changes v2: - fix w
From: Quirin Gylstorff <quirin.gylstorff@...> This will remove the requirement to use bullseye backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Changes v2: - fix w
|
By
Quirin Gylstorff
· #11033
·
|
|
[isar-cip-core][RFC] initramfs-crypt-hook: Add clevis for buster and bullseye
From: Quirin Gylstorff <quirin.gylstorff@...> This will remove the requirement to use bullseye backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .../preferences.bul
From: Quirin Gylstorff <quirin.gylstorff@...> This will remove the requirement to use bullseye backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .../preferences.bul
|
By
Quirin Gylstorff
· #11027
·
|
|
[isar-cip-core][PATCH v6 3/7] start-qemu.sh: Create a tpm2 device
After creating 8 keys/Images the 9th time you want to add a key to a new the TPM will throw a error. Quirin
After creating 8 keys/Images the 9th time you want to add a key to a new the TPM will throw a error. Quirin
|
By
Quirin Gylstorff
· #11000
·
|
|
[isar-cip-core][PATCH v6 3/7] start-qemu.sh: Create a tpm2 device
This was for debugging purposes as the TPM is no longer accessible after a number of keys entered. Quirin
This was for debugging purposes as the TPM is no longer accessible after a number of keys entered. Quirin
|
By
Quirin Gylstorff
· #10994
·
|
|
[isar-cip-core][PATCH v2 2/2] efibootguard: use debian folder from salsa
From: Quirin Gylstorff <quirin.gylstorff@...> To avoid package name conflicts between cip-core and Debian upstream use the debian folder from upstream to build efibootguard. Signed-off-by: Qui
From: Quirin Gylstorff <quirin.gylstorff@...> To avoid package name conflicts between cip-core and Debian upstream use the debian folder from upstream to build efibootguard. Signed-off-by: Qui
|
By
Quirin Gylstorff
· #10979
·
|
|
[isar-cip-core][PATCH v2 0/2] Enable Images based on Debian 12
From: Quirin Gylstorff <quirin.gylstorff@...> Add ci builds for bookworm Change efibootguard build to use debian folder from salsa Changes v2: - rebase onto next - always build efibootguard Qu
From: Quirin Gylstorff <quirin.gylstorff@...> Add ci builds for bookworm Change efibootguard build to use debian folder from salsa Changes v2: - rebase onto next - always build efibootguard Qu
|
By
Quirin Gylstorff
· #10978
·
|
|
[isar-cip-core][PATCH v2 1/2] Enable Images based on Debian 12 (bookworm)
From: Quirin Gylstorff <quirin.gylstorff@...> This will add prelimitary support for the debian 12 aka bookworm. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.ym
From: Quirin Gylstorff <quirin.gylstorff@...> This will add prelimitary support for the debian 12 aka bookworm. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.ym
|
By
Quirin Gylstorff
· #10977
·
|
|
[isar-cip-core][PATCH v6 7/7] Add README for encrypted partitions
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- doc/README.tpm2.encryption.md | 55 +++++++++++++++++++++++++++++++++++ 1 file c
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- doc/README.tpm2.encryption.md | 55 +++++++++++++++++++++++++++++++++++ 1 file c
|
By
Quirin Gylstorff
· #10970
·
|
|
[isar-cip-core][PATCH v6 5/7] overlay: add prerequisite 'encrypt_partition'
From: Quirin Gylstorff <quirin.gylstorff@...> If /var shall be encrypted encrypt_partition needs to be executed before the overlay script. If the prerequisite is not available the overlay scri
From: Quirin Gylstorff <quirin.gylstorff@...> If /var shall be encrypted encrypt_partition needs to be executed before the overlay script. If the prerequisite is not available the overlay scri
|
By
Quirin Gylstorff
· #10969
·
|
|
[isar-cip-core][PATCH v6 3/7] start-qemu.sh: Create a tpm2 device
From: Quirin Gylstorff <quirin.gylstorff@...> This allows testing the partition encryption with qemu. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- start-qemu.sh | 27 ++++
From: Quirin Gylstorff <quirin.gylstorff@...> This allows testing the partition encryption with qemu. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- start-qemu.sh | 27 ++++
|
By
Quirin Gylstorff
· #10968
·
|
|
[isar-cip-core][PATCH v6 6/7] .gitlabci: Add ci build
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a
|
By
Quirin Gylstorff
· #10967
·
|
|
[isar-cip-core][PATCH v6 0/7] Encrypt Partition in initramfs
From: Quirin Gylstorff <quirin.gylstorff@...> This encrypts a partition with LUKS and uses the TPM2 to unlock the partition during boot. Adapt start-qemu to support tpm2. The implementation us
From: Quirin Gylstorff <quirin.gylstorff@...> This encrypts a partition with LUKS and uses the TPM2 to unlock the partition during boot. Adapt start-qemu to support tpm2. The implementation us
|
By
Quirin Gylstorff
· #10966
·
|
|
[isar-cip-core][PATCH v6 2/7] KConfig: add option to encrypt data partitions
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Kconfig | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Kconfig b
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Kconfig | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Kconfig b
|
By
Quirin Gylstorff
· #10965
·
|
|
[isar-cip-core][PATCH v6 4/7] Add initramfs hook to encrypt a partition
From: Quirin Gylstorff <quirin.gylstorff@...> This creates a new luks encrypted ext4 partition with a the key stored in the tpm2. The initial key is randomly generated and removed from the LUK
From: Quirin Gylstorff <quirin.gylstorff@...> This creates a new luks encrypted ext4 partition with a the key stored in the tpm2. The initial key is randomly generated and removed from the LUK
|
By
Quirin Gylstorff
· #10964
·
|
|
[isar-cip-core][PATCH v6 1/7] use bullseye backports for systemd-cryptenroll
From: Quirin Gylstorff <quirin.gylstorff@...> Systemd >= 251 is required for systemd-cryptenroll. This version is part of backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...
From: Quirin Gylstorff <quirin.gylstorff@...> Systemd >= 251 is required for systemd-cryptenroll. This version is part of backports. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...
|
By
Quirin Gylstorff
· #10963
·
|
|
[isar-cip-core][PATCH v5 6/6] Add README for encrypted partitions
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- doc/README.tpm2.encryption.md | 55 +++++++++++++++++++++++++++++++++++ 1 file c
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- doc/README.tpm2.encryption.md | 55 +++++++++++++++++++++++++++++++++++ 1 file c
|
By
Quirin Gylstorff
· #10962
·
|
|
[isar-cip-core][PATCH v5 5/6] .gitlabci: Add ci build
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- .gitlab-ci.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a
|
By
Quirin Gylstorff
· #10961
·
|
|
[isar-cip-core][PATCH v5 3/6] Add initramfs hook to encrypt a partition
From: Quirin Gylstorff <quirin.gylstorff@...> This creates a new luks encrypted ext4 partition with a the key stored in the tpm2. The initial key is randomly generated and removed from the LUK
From: Quirin Gylstorff <quirin.gylstorff@...> This creates a new luks encrypted ext4 partition with a the key stored in the tpm2. The initial key is randomly generated and removed from the LUK
|
By
Quirin Gylstorff
· #10960
·
|
|
[isar-cip-core][PATCH v5 2/6] start-qemu.sh: Create a tpm2 device
From: Quirin Gylstorff <quirin.gylstorff@...> This allows testing the partition encryption with qemu. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- start-qemu.sh | 27 ++++
From: Quirin Gylstorff <quirin.gylstorff@...> This allows testing the partition encryption with qemu. Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- start-qemu.sh | 27 ++++
|
By
Quirin Gylstorff
· #10959
·
|
|
[isar-cip-core][PATCH v5 1/6] KConfig: add option to encrypt data partitions
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Kconfig | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Kconfig b
From: Quirin Gylstorff <quirin.gylstorff@...> Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...> --- Kconfig | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Kconfig b
|
By
Quirin Gylstorff
· #10958
·
|