Project

General

Profile

Actions

action #133265

closed

[security][ALP] Manual Testing for ALP Dolomite Build 2.1

Added by emiler 10 months ago. Updated 10 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
2023-07-25
Due date:
% Done:

100%

Estimated time:
4.00 h
Difficulty:
Tags:

Description

We should do manual testing of the latest ALP Dolomite (Micro) build 2.1.

Steps:

  • Raw image setup with TPM
  • Fallback to password disk decryption when TPM is removed
  • Check audit.log for AVC deny

Feel free to add more bullet-points. Completed tasks are crossed-out.


Files

2023-07-25_10_08_33.png (108 KB) 2023-07-25_10_08_33.png Password Unlock Fallback emiler, 2023-07-25 08:10
2023-07-25_10_10_52.png (92.8 KB) 2023-07-25_10_10_52.png Missing TPM Boot emiler, 2023-07-25 08:11
audit.log (109 KB) audit.log emiler, 2023-07-25 08:32

Updated by emiler 10 months ago

The raw image is booting without issues. I followed the setup steps in the documentation, mainly changing BIOS to UEFI and adding an emulated TPM.
When TPM is later removed, it does fall back to password authentication and is able to unlock the disk and boot successfully. When re-added again, the system boots without any password prompt.

Actions #2

Updated by emiler 10 months ago

Here is a copy of audit.log after playing with the TPM fallback. I have also enabled root login via ssh to pull the log from the system, which works fine and without the need to modify anything in SELinux.

echo "PermitRootLogin yes" > /etc/ssh/sshd_config.d/root.conf
systemctl restart sshd
Actions #3

Updated by tjyrinki_suse 10 months ago

  • Tags set to alp
  • Status changed from Feedback to Resolved
  • Assignee deleted (emiler)
  • % Done changed from 0 to 100
  • Estimated time set to 4.00 h

Excellent work, thank you for testing milestone 2 candidate!

Actions

Also available in: Atom PDF