LWN.net Logo

Forward secure sealing

Forward secure sealing

Posted Aug 24, 2012 0:50 UTC (Fri) by mezcalero (subscriber, #45103)
In reply to: Forward secure sealing by richmoore
Parent article: Forward secure sealing

This will be noticed during verification and reported. It's then up to the admin to either consider that OK, or not.


(Log in to post comments)

Forward secure sealing

Posted Aug 26, 2012 5:09 UTC (Sun) by ikm (subscriber, #493) [Link]

What about the sealing key? Wouldn't journald fast-forward it when it boots into the distant future, and then would have no way to revert it back once ntp returns the box back into the present time?

Forward secure sealing

Posted Aug 26, 2012 5:22 UTC (Sun) by Cyberax (✭ supporter ✭, #52523) [Link]

Yup. That's a problem, but that doesn't happen that often in practice (and journald would be able tolerate small jumps just fine). In case a big jump happens, journald can insert authenticated record about it.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds