Posted Aug 26, 2012 5:09 UTC (Sun) by ikm (subscriber, #493)
[Link]
What about the sealing key? Wouldn't journald fast-forward it when it boots into the distant future, and then would have no way to revert it back once ntp returns the box back into the present time?
Forward secure sealing
Posted Aug 26, 2012 5:22 UTC (Sun) by Cyberax (✭ supporter ✭, #52523)
[Link]
Yup. That's a problem, but that doesn't happen that often in practice (and journald would be able tolerate small jumps just fine). In case a big jump happens, journald can insert authenticated record about it.