Skip to content

Commit f66dd2b

Browse files
committed
initrd/bin/kexec-unseal-key: never show final PCRs content but in DEBUG mode/Recovery Shell
Next steps on this is introspection and PCRs reconstruction helpers, which will output in DEBUG and be usable from recovery shell. We have to keep in mind that providing those tools is useful in DEBUG mode and for users having access to Recovery Shell. But currently, having access to cbmem -L output and final PCRs content is making it too easy for Evil Maid to know what needs to be hardcoded to pass measured boot. Signed-off-by: Thierry Laurion <insurgo@riseup.net>
1 parent de7e2bb commit f66dd2b

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

initrd/bin/kexec-unseal-key

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ for tries in 1 2 3; do
4141
exit 0
4242
fi
4343

44-
pcrs
44+
DEBUG $(pcrs)
4545
warn "Unable to unseal disk encryption key"
4646
done
4747

0 commit comments

Comments
 (0)