Re: measured boot / fTPM and OpenWrt One

2024-05-10 Thread Michael Richardson
Daniel Golle wrote: >> Well, that's certainly true. It is not always possible to talk to the >> outside world from inside that initial boot enclave. That's the detail that >> we need. >> Do we even have a spare GPI(o) pin that can be used for this? >> (It can't be used for

Re: measured boot / fTPM and OpenWrt One

2024-05-10 Thread Daniel Golle
Hi Michael, On Fri, May 10, 2024 at 03:03:27PM -0400, Michael Richardson wrote: > > Daniel Golle wrote: > > On Mon, Apr 29, 2024 at 03:04:37PM -0400, Michael Richardson wrote: > >> > >> {sorry for the long delay, been unwell} > >> > >> Bjørn Mork wrote: > >> > Maybe it i

measured boot / fTPM and OpenWrt One

2024-05-10 Thread Michael Richardson
Daniel Golle wrote: > On Mon, Apr 29, 2024 at 03:04:37PM -0400, Michael Richardson wrote: >> >> {sorry for the long delay, been unwell} >> >> Bjørn Mork wrote: >> > Maybe it is possible to deploy the system with secure boot and a >> > protected IDevId key by default,