Skip to content

Commit 5a52c67

Browse files
committed
initrd/bin/kexec-unseal-key: never show final PCRs content but in DEBUG mode/Recovery Shell
Next steps on this is introspection and PCRs reconstruction helpers, which will output in DEBUG and be usable from recovery shell. We have to keep in mind that providing those tools is useful in DEBUG mode and for users having access to Recovery Shell. But currently, having access to cbmem -L output and final PCRs content is making it too easy for Evil Maid to know what needs to be hardcoded to pass measured boot. Signed-off-by: Thierry Laurion <insurgo@riseup.net>
1 parent 9dc8e79 commit 5a52c67

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

initrd/bin/kexec-unseal-key

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ for tries in 1 2 3; do
3838
exit 0
3939
fi
4040

41-
pcrs
41+
DEBUG $(pcrs)
4242
warn "Unable to unseal disk encryption key"
4343
done
4444

0 commit comments

Comments
 (0)