Re: TPMs, measured boot and remote attestation in Fedora

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, Apr 22, 2016 at 7:31 AM, Josh Boyer <jwboyer@xxxxxxxxxxxxxxxxx> wrote:
> On Fri, Apr 22, 2016 at 2:35 AM, Matthew Garrett <mjg59@xxxxxxxxxxxxx> wrote:
>> On Thu, Apr 21, 2016 at 02:35:21PM +0200, Harald Hoyer wrote:
>>> On 08.04.2016 18:56, Matthew Garrett wrote:
>>> > initrd is certainly a more difficult one. One thing we can do is work on
>>> > making dracut builds reproducible - that way they should be consistent
>>> > across identical machines in a cluster.
>>> >
>>>
>>> dracut already supports reproducible builds:
>>> $ man dracut
>>> […]
>>>        --reproducible
>>>            Create reproducible images.
>>>
>>> needs cpio with "--reproducible" support though
>>
>> Oh, wonderful! Is there a reason that isn't default in Fedora?
>
> I'm guessing because it changes the default away from HostOnly mode,
> which is something we consciously switched to several releases ago.

--hostonly initramfs on F23, 30M
--reproducible initramfs on F24, 50M
--no hostonly initramfs on F24, 50M

So this might mean boot partitions need to get bigger, which is
actually currently being discussed on anaconda-devel@

I'm finding that by default right now F23 initramfs is 30M, F24
initramfs is 50M, so something's changed for Fedora 24.

-- 
Chris Murphy
--
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
http://lists.fedoraproject.org/admin/lists/devel@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux