julian
|
1b86750b0d
|
docs(wiki): firmware/dbx-vs-TPM hardening + create disk-os-hardening page
Real-world park-buzi episode: a UEFI dbx update (delivered via fwupd/LVFS,
NOT apt) revoked a stale GRUB -> panic, and moved PCR 7 -> broke TPM-sealed
LUKS auto-unlock -> passphrase prompt. Recovered by re-sealing PCR 7.
- appliance-provisioning.md: extend the §4 re-seal runbook to name dbx; new
§4a (fwupd-not-apt, GRUB-panic ordering, PCR-7 re-seal, operator lockdown:
mask fwupd + remove firmware-updater snap + BIOS-password + passphrase
escrow) incl. the --test-passphrase-silently-passes-via-TPM trap
(--disable-external-tokens); gotchas #12/#13.
- disk-os-hardening.md: NEW — resolves a long-dangling wikilink referenced
from ~18 pages. The *why* of host hardening (5 controls + firmware lockdown);
commands stay in appliance-provisioning; reconciliation remains the primary
anti-fraud control.
- index.md: expand the disk-os-hardening catalog line.
- log.md: two note entries.
Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
|
2026-06-30 15:21:32 +02:00 |
|