By Matthew Garrett, February 26, 2016
Originally published on the CoreOS blog (archived copy) . Re-published with the authors' permission.
As a part of our fundamental mission of securing the backend of the Internet, CoreOS has joined the Trusted Computing Group (TCG), an international industry standards group. The TCG is a not-for-profit organization formed to develop, define and promote open, vendor-neutral, global industry standards, supportive of a hardware-based root of trust, for interoperable trusted computing platforms.
CoreOS believes in working together with industry leaders to cooperate under standard models to implement best practices, while also enabling users with interoperability and flexibility. In addition, with security at top of mind in everything we do, it is a natural choice to be a part of the TCG.
"Industry standards are of utmost importance when it comes to maintaining best practices in security," said Mark Schiller, executive director, Trusted Computing Group. "We are thrilled to have CoreOS join the TCG as a member of our global network, and collaborate with other industry leaders to support a hardware-based root of trust, for interoperable trusted computing platforms."
This is another step in part of our work with Tectonic with Distributed Trusted Computing. By thoughtful collaboration with the industry we can ensure best practices are in place in the cryptographic chain of trust at each layer of the stack. The Tectonic Distributed Trusted Computing platform performs validation of each component of the boot process, making it possible to ensure that individual computers have not been tampered with before being permitted to join the cluster. The state of each individual container is recorded at initialization time in order to provide a cryptographically verifiable audit trail of every container that a cluster has launched. Combined with the existing security features of CoreOS, administrators can deploy containers with confidence that they can trust the underlying platform. The same trusted computing components are also used to handle deploying secrets to systems in a secure way, reducing manual involvement and simplifying the process of building out a cluster.
This is also about incorporating the work we do for the benefit of the community — both in upstream projects we work closely with and to overall make it easier for other projects to develop TPM-based features to come to avenues of improved user security.
We will be participating on a panel, Things to do with the TPM, at TCG Day at RSA Conference San Francisco on Monday, February 29, 2016 at 10:10 a.m. PT.
The panel, moderated by Paul Roberts, founder and editor-in-chief of Security Ledger, will look at the newest and best ways to implement the TPM. CoreOS will be on the panel joined by Paul England, software architect at Microsoft.
If you are at RSA, please come to the panel and meet us.