update TODO

This commit is contained in:
Lennart Poettering 2022-10-14 21:21:46 +02:00
parent f44ed151c6
commit a67a50e8f4

5
TODO
View file

@ -451,9 +451,8 @@ Features:
and via the time window TPM logic invalidated if node doesn't keep itself and via the time window TPM logic invalidated if node doesn't keep itself
updated, or becomes corrupted in some way. updated, or becomes corrupted in some way.
* Always measure the LUKS rootfs volume key into PCR 15, and derive the machine * in the initrd, once the rootfs encryption key has been measured to PCR 15,
ID from it securely. This would then allow us to bind secrets a specific derive default machine ID to use from it, and pass it to host PID 1.
system securely.
* tree-wide: convert as much as possible over to use sd_event_set_signal_exit(), instead * tree-wide: convert as much as possible over to use sd_event_set_signal_exit(), instead
of manually hooking into SIGINT/SIGTERM of manually hooking into SIGINT/SIGTERM