Skip to content

tang: skip storing adv when server supports tang_pub - #576

Open
sarroutbi wants to merge 1 commit into
latchset:masterfrom
sarroutbi:tang-pub-skip-adv-storage
Open

sarroutbi wants to merge 1 commit into
latchset:masterfrom
sarroutbi:tang-pub-skip-adv-storage

Conversation

@sarroutbi

@sarroutbi sarroutbi commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

At provisioning time (clevis encrypt tang), call GET /version on the Tang server. When features.tang_pub is true, create a new-format binding that stores only the Tang URL and key identifier — the full advertisement is not persisted in the JWE header. When /version returns 404 or tang_pub is absent, fall back to current behavior.

This significantly reduces the metadata written to the LUKS header while maintaining full backward compatibility: when the capability header is absent or the advertisement is provided offline, the adv is stored as before.

Encrypt side:

  • Call /version to check if tang_pub feature is enabled:
{
  "features": {
    "tang_pub": true
  },
  "tang_version": "15"
}
  • Conditionally omit adv from JWE header when tang_pub is available

Decrypt side:

  • Make adv extraction optional (non-fatal when absent)
  • Extract tang_pub from recovery response and validate its thumbprint
  • Fail fast if adv IS present but kid does not match (tamper detection)
  • Fall back to stored adv for servers without tang_pub support

In order to check that Server public key is not being dumped, next command can be performed on Clevis client:

cryptsetup token export --token-id 0 /dev/nvme0n1p3 | jq -r '.jwe.protected' | jose b64 dec -i- | jq '.clevis.tang | keys'

In legacy case, output shown was:

[
  "adv",
  "url"
]

Meanwhile, in case new Tang server is used (latchset/tang#164), output is:

[
  "url"
]

Tests have been performed in Fedora 44, with encrypted root filesystem, and different scenario:
1 - Tang sending tang_pub, legacy Clevis: Clevis stores server public key in disk metadata
2 - Tang sending tang_pub, Clevis patched version: Clevis does not store server public key in disk metadata, disk unlock happens through tang_pub
3 - Legacy Tang, Clevis patched version: As Tang not sending tang_pub, Clevis stores server public key in disk metadata, and uses it for recovery

@sarroutbi
sarroutbi force-pushed the tang-pub-skip-adv-storage branch from 8fc9ecc to dc8aefe Compare September 23, 2026 09:40
@sarroutbi

sarroutbi commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator Author

/packit test

@packit-as-a-service

Copy link
Copy Markdown

There appears to be a syntax error in the command provided. Please refer to the Packit documentation or use the /packit help command.

@sarroutbi
sarroutbi force-pushed the tang-pub-skip-adv-storage branch 2 times, most recently from 7a00936 to 25bbc0b Compare September 24, 2026 08:31
@sarroutbi
sarroutbi marked this pull request as ready for review September 24, 2026 10:30
@sarroutbi
sarroutbi force-pushed the tang-pub-skip-adv-storage branch from 25bbc0b to 75ebee1 Compare September 24, 2026 11:28
At provisioning time (clevis encrypt tang), call GET /version on the
Tang server. When features.tang_pub is true, create a new-format
binding that stores only the Tang URL and key identifier — the full
advertisement is not persisted in the JWE header. When /version
returns 404 or tang_pub is absent, fall back to current behavior.

At recovery time (clevis decrypt tang), check the binding format:
new-format bindings extract tang_pub from the POST /rec/$kid response
for ECMR recovery; legacy bindings use the stored advertisement
unchanged. If a new-format recovery fails because tang_pub is missing
from the server response, fail clearly without silent fallback.

clevis luks regen automatically migrates eligible legacy bindings to
the new format by re-querying /version during re-encryption.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Sergio Arroutbi <sarroutb@redhat.com>
@sarroutbi
sarroutbi force-pushed the tang-pub-skip-adv-storage branch from 75ebee1 to 1c30171 Compare September 24, 2026 11:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant