From owner-freebsd-arch@freebsd.org Sun Oct 22 22:31:42 2017 Return-Path: Delivered-To: freebsd-arch@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 86694E3833F for ; Sun, 22 Oct 2017 22:31:42 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-qt0-x229.google.com (mail-qt0-x229.google.com [IPv6:2607:f8b0:400d:c0d::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 44100779FA for ; Sun, 22 Oct 2017 22:31:42 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-qt0-x229.google.com with SMTP id 8so24129997qtv.1 for ; Sun, 22 Oct 2017 15:31:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=bSyhe9uYPpe7TOlfCzaPDkrNgbYDdmbbs/LdFqmQ8Sk=; b=e4hbPJ7fOT9GE8X35njVH+ahYhtbSVCkhIY6nkC03CXws/BCRJ0T+RD7nMBS5RIzfo yUBzc39yerQu5Ym95YRwcku9uBRYcv1FN5/j34xxnNmsRvGq3oqvnotANbabplzNdVot jpNH5yojNwwpT7YLAfNP42rJqekWPB0AZ3j6bLLs2Lr2t0Gsqr9SoX2oMyOWwueLh11U JwrGW/Pji8namtmd45JT3j6O8OSwO1tv7IbxPXfltPKXI9nM5PENPZKQCrO/YSNFP7et os1LAIvQ1P+Bv2iscfMRf6LY9FClCRYzY9GDMGMrUEUffauMXbT2jgWAdlh21tvQR4qx Ggcg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=bSyhe9uYPpe7TOlfCzaPDkrNgbYDdmbbs/LdFqmQ8Sk=; b=F4mj/K+q2/OaFC8OSX8hJqrnFhHuXgS+qXrn3vrGug0lEDOEsMA4Hpk1tFxLElU31V +5Hk5n5Zi2uUIxbrisDBCynjXJMzXU2H8bpKWWAZUNfZmQGNEJwec5TA1mTNov1o7AW8 3qS3WakQPOVIrXb6Ku9MFZR8+zcLqjzzmVhkRINjaMVzNSFEzV536RrfwxtSJ7S/pcIv KTxWXj+wyWGQ+JVGsVr8MDvT0jcuz2o6fbGbSJ5Gvm3Zuj/sKdwDOwEpbVMgt1Gi31zo dqM1hKI7c2TDrDjzHPqEk4EDFnxGz2Xuz7XYjeg4Y0MoLrImn5kRRjJTZLD6il1eKV/p nxXw== X-Gm-Message-State: AMCzsaUndXRDOl93JCZxJ0Nnmd7XfbUusROo9R1Ob1YnMRkUE52/ju6j VFNagst0UvIktkD9ovXv84a97A== X-Google-Smtp-Source: ABhQp+RxR23Uchv3/7x9v7yj6V5tlmfgNjACTmSN6H/nMM6RJbSZb/DKulUrNfLsO5q+gQVJTJTdPw== X-Received: by 10.237.42.230 with SMTP id t93mr17709929qtd.317.1508711501122; Sun, 22 Oct 2017 15:31:41 -0700 (PDT) Received: from mutt-hbsd (pool-100-16-230-154.bltmmd.fios.verizon.net. [100.16.230.154]) by smtp.gmail.com with ESMTPSA id k79sm3809705qke.28.2017.10.22.15.31.40 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Sun, 22 Oct 2017 15:31:40 -0700 (PDT) Date: Sun, 22 Oct 2017 18:31:33 -0400 From: Shawn Webb To: Eric McCorkle Cc: "freebsd-hackers@freebsd.org" , freebsd-security@freebsd.org, freebsd-arch@freebsd.org Subject: Re: Trust system write-up Message-ID: <20171022223133.nkcpkhtl7s7kzgs5@mutt-hbsd> References: <1a9bbbf6-d975-0e77-b199-eb1ec0486c8a@metricspace.net> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="zanh2tn2izgbdqkn" Content-Disposition: inline In-Reply-To: <1a9bbbf6-d975-0e77-b199-eb1ec0486c8a@metricspace.net> X-Operating-System: FreeBSD mutt-hbsd 12.0-CURRENT FreeBSD 12.0-CURRENT X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: NeoMutt/20170912 (1.9.0) X-BeenThere: freebsd-arch@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Discussion related to FreeBSD architecture List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 22 Oct 2017 22:31:42 -0000 --zanh2tn2izgbdqkn Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Oct 22, 2017 at 10:14:40PM +0000, Eric McCorkle wrote: > Hello everyone, >=20 > The following is a write-up of my current design for a public-key trust > system: >=20 > https://www.metricspace.net/files/freebsd_trust.pdf >=20 > Some of you are certainly familiar with some or all of this; > I've discussed parts of it before on -hackers and -security, and I > discussed it in greater detail in BoF sessions at vBSDCon. It seems > things are heating up in this direction, so I'd like to get this out > there and get discussion and feedback. >=20 > I plan on undertaking work on this in the very near future, especially > since the commit-train for GELI EFI is ready to arrive in HEAD. >=20 > A bit about the format: this is sort of the "meat" of what I hope will > be a paper some day, but it's still an initial draft. Moreover, it > talks about things I'm planning as if they exist, mainly because I don't > want to have to go back and rewrite everything in the future. In > reality, most of what I talk about is just a proposal at this point, > with a few bits being implemented as a PoC here and there. >=20 > Please read and consider the designs I've proposed. I welcome any > feedback and suggestions. I'll give it a week minimum from today before > I resume any work on this stuff. Hey Eric, Thank you so much for working on this. I do have a few questions. I'm curious about the rational behind not requiring expiration of trusted root key material. Can jails contain a different trust chain than the host? Thanks, --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --zanh2tn2izgbdqkn Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKrq2ve9q9Ia+iT2eaoRlj1JFbu4FAlntHEIACgkQaoRlj1JF bu585g//SLA5OM7zRX/0SziOYf5ref5HARdM9T0BjmEejcLGA9ZgcwH3i0krPJXY IznjVMVlIpXcqUA5CYrNjSaaxs1h2TIS/wxVrhPrtpM8NOezZNxOT0fm8IaG624h V1E0YO+TYn2Iy3yBrzAJI+kFnJ998cvTauapAWxtvpo3AJUfDI/Lx02yEbq21U+J JJV5vvYE029on0irPWepCJdRz9hiwUCI/f9t3yXlJLae01RgJObwpU+SXgtGOx43 e/HO/za/EEgDmB7njSUyw0sw4QWm7F1VXhemClP9jq7C+yedIkExJFfE6VynRDta crR9StOctmkdnf4M/48NGmGUndRBLDrwf0b6+gmSuZTrzP4WOkYMK5bJYJPA2xx5 DbRCOpqIc+Jvr+Qfnr2mXnUKmjM+WWo/FCx/pc7eFMaNyFQpSBpBptO/syuOTvJU MAmCBdreT56Tz1uce7JH6Q3sOQ3C3HLFn4kB1F5l4kTskiZSMOykFEUmgEfz75kF gnXCT/dJVfsYQCbGeQlU2+wCK1tt03p+4pcSyCK7cMdSd7RCjrt7H2G44UGet+lH fH3Q0FuCxfD8TuLaG5az8NpdrAB24cPPM8wghyunqDllNqb19731d6fK4+EJBmbF OOniNXf0EA3CalTN1dtRluABHZyxWidZKudUot77xJ1jqlPLDKM= =vbis -----END PGP SIGNATURE----- --zanh2tn2izgbdqkn--