3 ms·
> 1) is there a simple key destroy function? Just rm the key file. TPM sealed secrets are never actually stored inside the TPM, they are just files with strong
by Foxboron 3y ago
> 1) is there a simple key destroy function?
Just rm the key file. TPM sealed secrets are never actually stored inside the TPM, they are just files with strong encrypted that only the TPM can decrypt. So deleting the key file removes your ability to recreate the key.
> 2) if somebody gains remote login access to the host with root, noting they can't exfiltrate the keys, can they subvert process chains to claim linkage to the ssh-agent process?
Possibly, yes.