LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-28-2024, 07:06 AM   #1
displace
Member
 
Registered: Jan 2013
Location: EU
Distribution: Debian
Posts: 268

Rep: Reputation: 25
Very very trusted platform module


Hello, sorry for the lack of a better topic title.

I'm looking for a hardware device to secure a rack linux server in a certain way, and I'm trying to find out what to use.
The device has to offer the following security features:
  • It houses a cryptographic key in a secure memory location that doesn't suffer from RAM "burn-in".
  • Upon boot, GRUB should be able to retrieve the cryptographic key automatically for the purpose of decrypting a LUKS-encrypted rootfs partition (/boot included).
  • It offers a way to securely wipe the stored cryptographic key(s) in a panic situation (i.e. a GPIO pin for chassis intrusion or via API)
  • It has to have backup power available, so that in case the main power is lost, the device continues to operate and detect physical intrusions
  • If the backup power is lost (battery depletes) then the keys are automatically wiped

Does anything like this exist? A TPM module may come close, but it doesn't have backup power, and if the power is lost it doesn't erase the stored keys.
 
Old 02-28-2024, 08:29 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,918

Rep: Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318Reputation: 7318
No, I think it does not exist, you need to implement it, or at least there are some parts which should be created.
Quote:
It offers a way to securely wipe the stored cryptographic key(s) in a panic situation (i.e. a GPIO pin for chassis intrusion or via API)
I have no idea how can it be solved without OS and without modifying the BIOS.
Probably you will need a different approach.
 
  


Reply

Tags
encryption, luks, tpm



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Trusted Platform Module for Dual Boot? tnandy Linux - Hardware 1 09-02-2020 11:13 PM
[SOLVED] Trusted Platform Module (TPM) setting on new computer deretsigernu Linux - General 1 05-19-2019 12:18 PM
Is it feasible to sign RPM/Deb using a cert issued by Trusted CA or signing with a GPG Key Pair Signed by a Trusted CA ktalinki Linux - Security 1 07-12-2018 07:46 PM
LXer: Linux and the Trusted Platform Module (TPM) LXer Syndicated Linux News 1 09-28-2009 03:00 PM
Trusted Computing Platform, Palladium and the Consortium Corporal Linux - Security 1 10-16-2005 03:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration