The Linux v6.7 merge window has been open for a few days now, here are the SELinux and audit highlights:
https://paul-moore.com/blog/d/2023/11/linux_v67_merge_window.html
So we merged this → https://github.com/systemd/systemd/pull/28891 into systemd today. I like to believe that this is a major step towards closing the "TPM gap" we have on Linux toward other OSes. It can automatically generate an automatic TPM2 PCR policy from various inputs covering the PCRs that generally are hard to predict by the OS vendor, i.e. things like local firmware versions, extension cards and so on. It stores this in an NV index in the TPM. Things like LUKS can then be locked against that NV index.
Reminder, the big day starts Monday 8:30. You can still join remotely! @netdev01 0x17 https://netdevconf.info/0x17/pages/sessions.html #netdevconf
Video overview of #Incus 0.2 is live now!
https://www.youtube.com/watch?v=ePvhWNv-gp4
"Microsoft Azure Boost: Image-based Linux powering the Azure fleet", a deep dive into a tailored Linux distro focused on security that provides offloading and acceleration. A great talk by @bluca at @allsystemsgo!
A lot of stuff is introduced: Linux hardening, remote attestation, SELinux, dm-verity, IPE, LUKS, fs-verity, overlayfs, systemd portable services, soft reboot, ARM, FPGA, DPDK...
Slides: https://cfp.all-systems-go.io/all-systems-go-2023/talk/7URRNC/
Recording: https://youtu.be/iB-wRdC8zNs