Repository navigation
Conversation
sarroutbi
force-pushed
the
tang-pub-skip-adv-storage
branch
from
September 23, 2026 09:40
8fc9ecc to
dc8aefe
Compare
Collaborator
Author
|
/packit test |
|
There appears to be a syntax error in the command provided. Please refer to the Packit documentation or use the |
sarroutbi
force-pushed
the
tang-pub-skip-adv-storage
branch
2 times, most recently
from
September 24, 2026 08:31
7a00936 to
25bbc0b
Compare
sarroutbi
marked this pull request as ready for review
September 24, 2026 10:30
sarroutbi
force-pushed
the
tang-pub-skip-adv-storage
branch
from
September 24, 2026 11:28
25bbc0b to
75ebee1
Compare
At provisioning time (clevis encrypt tang), call GET /version on the Tang server. When features.tang_pub is true, create a new-format binding that stores only the Tang URL and key identifier — the full advertisement is not persisted in the JWE header. When /version returns 404 or tang_pub is absent, fall back to current behavior. At recovery time (clevis decrypt tang), check the binding format: new-format bindings extract tang_pub from the POST /rec/$kid response for ECMR recovery; legacy bindings use the stored advertisement unchanged. If a new-format recovery fails because tang_pub is missing from the server response, fail clearly without silent fallback. clevis luks regen automatically migrates eligible legacy bindings to the new format by re-querying /version during re-encryption. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Sergio Arroutbi <sarroutb@redhat.com>
sarroutbi
force-pushed
the
tang-pub-skip-adv-storage
branch
from
September 24, 2026 11:35
75ebee1 to
1c30171
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
At provisioning time (clevis encrypt tang), call GET /version on the Tang server. When features.tang_pub is true, create a new-format binding that stores only the Tang URL and key identifier — the full advertisement is not persisted in the JWE header. When /version returns 404 or tang_pub is absent, fall back to current behavior.
This significantly reduces the metadata written to the LUKS header while maintaining full backward compatibility: when the capability header is absent or the advertisement is provided offline, the adv is stored as before.
Encrypt side:
tang_pubfeature is enabled:Decrypt side:
In order to check that Server public key is not being dumped, next command can be performed on Clevis client:
In legacy case, output shown was:
Meanwhile, in case new Tang server is used (latchset/tang#164), output is:
Tests have been performed in Fedora 44, with encrypted root filesystem, and different scenario:
1 - Tang sending
tang_pub, legacy Clevis: Clevis stores server public key in disk metadata2 - Tang sending
tang_pub, Clevis patched version: Clevis does not store server public key in disk metadata, disk unlock happens throughtang_pub3 - Legacy Tang, Clevis patched version: As Tang not sending
tang_pub, Clevis stores server public key in disk metadata, and uses it for recovery