Posted Aug 23, 2012 11:48 UTC (Thu) by richmoore (subscriber, #53133)
Parent article: Forward secure sealing
I wonder what the effect of the system clock going backwards (eg. because of updates from ntp, or a negative leap second) would be on the key generation. These are rare, but 'expected' events.
Posted Aug 24, 2012 0:50 UTC (Fri) by mezcalero (subscriber, #45103)
[Link]
This will be noticed during verification and reported. It's then up to the admin to either consider that OK, or not.
Forward secure sealing
Posted Aug 26, 2012 5:09 UTC (Sun) by ikm (subscriber, #493)
[Link]
What about the sealing key? Wouldn't journald fast-forward it when it boots into the distant future, and then would have no way to revert it back once ntp returns the box back into the present time?
Forward secure sealing
Posted Aug 26, 2012 5:22 UTC (Sun) by Cyberax (✭ supporter ✭, #52523)
[Link]
Yup. That's a problem, but that doesn't happen that often in practice (and journald would be able tolerate small jumps just fine). In case a big jump happens, journald can insert authenticated record about it.