[DOCUMENTATION NEEDED] [REVIEW NEEDED] feat: implement tpm sealed sshd host keys
this allows one to verify cryptographically that the initramfs has NOT been modified, and prevents attackers from doing a MITM attack or inserting a keylogger into the initramfs. the key can not be read without booting the machine, and if you modify the initramfs, the key wont be released.
this implementation is somewhat sloppy, as i just need it for my desktop and server right now. even though it passes the tests, please review thoroughly before merging.
合并状态:未合并 关闭于 2025-01-05 4 条评论