[keylime] Add plugin for Keylime remote attestation - #4423
Open
suraj-cmd wants to merge 1 commit into
Open
Conversation
Keylime is packaged for Fedora and RHEL and provides TPM-based remote attestation, but sos has no plugin for it and no other plugin references it. An sosreport from a verifier, registrar or agent host currently contains none of its configuration or service state. The paths and unit names are taken from the upstream packaging: services/keylime-tmpfiles.conf creates /etc/keylime with the per-component .conf.d drop-in directories and /var/lib/keylime at mode 0700, and the units are keylime_agent, keylime_registrar and keylime_verifier. /var/lib/keylime is deliberately not copied. keylime/ca_util.py writes the deployment CA key there as <name>-private.pem, and the same tree holds decrypted payloads. A recursive listing is taken instead, which still shows the CA state and file ownership. PEM files are added to the forbidden paths so no key material can be collected from either location. Signed-off-by: Suraj Patil <surajpatil522@gmail.com>
|
Congratulations! One of the builds has completed. 🍾 You can install the built RPMs by following these steps:
Please note that the RPMs should be used only in a testing environment. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Keylime is packaged for Fedora and RHEL and provides TPM-based remote
attestation, but sos has no plugin for it and no other plugin references it. An
sosreport from a verifier, registrar or agent host currently contains none of
its configuration or service state.
The paths and unit names are taken from the upstream packaging:
services/keylime-tmpfiles.confcreates/etc/keylimewith the per-component.conf.ddrop-in directories and/var/lib/keylimeat mode 0700, and theunits are
keylime_agent,keylime_registrarandkeylime_verifier./var/lib/keylimeis deliberately not copied.keylime/ca_util.pywrites thedeployment CA key there as
<name>-private.pem, and the same tree holdsdecrypted payloads. A recursive listing is taken instead, which still shows the
CA state and file ownership. PEM files are added to the forbidden paths so no
key material can be collected from either location.
Paths and unit names come from upstream
services/keylime-tmpfiles.confanddocs/man/rather than a running deployment, so confirmation against apackaged install would be welcome — particularly whether the distribution
packages split the config differently.
Please place an 'X' inside each '[]' to confirm you adhere to our Contributor Guidelines