Hacker News new | ask | show | jobs
by walterbell 756 days ago
> doesn't seem to allow to rerun the provisioning config on an already existing machine

In theory, a generic existing machine could have been compromised by malware, in which case the configuration may not match the previously provisioned version.

With OS launch integrity to guarantee absence of tampering, and prove that current=expected config+binaries, it could be feasible to rerun provisioning config.