canonical / canonical/secboot

Expose an API for validating a key file

Open
#33 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

There is an internal API for validating key files already. Ideally this would be improved to make it more useful and then exposed for diagnostic purposes in the event that the TPM sealed key could not be unsealed, and should provide a hint as to whether the TPM isn't provisioned correctly, a new TPM sealed key is required, or the metadata associated with the PCR policy is invalid.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.