Tag
This hands-on deep dive explains NvPCRs in systemd v262, which are additional PCR-like registers in TPM's NV memory to address PCRs scarcity for security features like disk encryption and remote attestation, with a focus on the reworked secure design.
The article explains remote attestation using TPM to cryptographically verify the state of hosts, ensuring trusted boot and preventing compromised hardware from accessing networks. It covers the benefits and complexities of implementing measured boot and how it can be combined with encryption and mTLS for strong security guarantees.