Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #81953

Bug#1064839: Consider not using an ephemeral key or document its security model

From Luca Boccassi <bluca@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1064839: Consider not using an ephemeral key or document its security model
Date 2024-02-26 17:00 +0100
Message-ID <IbLyx-cMIf-7@gated-at.bofh.it> (permalink)
References <IbJwJ-cLxd-3@gated-at.bofh.it> <IbJwJ-cLxd-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, 26 Feb 2024 14:45:19 +0100 Julian Andres Klode <jak@debian.org>
wrote:
> Source: linux
> Severity: normal
> X-Debbugs-Cc: jak@debian.org
> 
> In https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040901 I asked
you
> to switch to an ephemeral key which was a misunderstanding from a
> discussion with xnox, which we still need to sort out fully.
> 
> Please either document how the buildds ensure that
> 
> - private key generation has enough, and high quality enough, entropy
> - private keys are safely erased after not being needed anymore
> 
> or revert to signing modules with the CA key and use MODVERSIONS
> and co to ensure that modules built for one ABI cannot be used
> with another.
> 
> I need to update the question in shim-review accordingly, I think
> I never reverted it or adjusted it, but it will likely take the
> form of the previous three paragraphs.
> 
> I sincerely apologize for causing this misunderstanding.

Are those really that hard of a problem to solve? Running any modern
kernel entropy shouldn't be an issue, certainly not on controlled
environment like the buildds - if an attacker has complete control of
the buildds environment, then we can pack up and go home, given the
kernel build is not reproducible. And likewise key handling could be
done in a non-swappable tmpfs tied to the lifetime of the build process
via a namespace, that ought to be enough for peace of mind?

Using an ephemeral key makes things so much simpler and nicer and
quicker at signing time, and so much simpler to reason about. One
kernel, one set of modules, and that's it.

-- 
Kind regards,
Luca Boccassi

Back to linux.debian.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Bug#1064839: Consider not using an ephemeral key or document its security model Julian Andres Klode <jak@debian.org> - 2024-02-26 14:50 +0100
  Bug#1064839: Consider not using an ephemeral key or document its security model Luca Boccassi <bluca@debian.org> - 2024-02-26 17:00 +0100

csiph-web