Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Break-glass recovery feature needed #138

Open
nicowilliams opened this issue Jul 29, 2021 · 0 comments
Open

Break-glass recovery feature needed #138

nicowilliams opened this issue Jul 29, 2021 · 0 comments

Comments

@nicowilliams
Copy link
Contributor

Break-glass recovery == change the dTPM or the entire device (but not local storage) of an enrolled device.

This requires decrypting enrolled assets as encrypted to an escrow agent's key, then re-encryption to the new EKpub. Decryption of enrolled assets with the escrow key might require off-line interactions, or executing complex EA policies, but sbin/attest-enroll should at least support use of trivial escrow agents.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant