3 ms·
How far up the stack does the verification go? Most secure boot stacks give up after the initramfs because disk images are usually mutable. Do you make any atte
by Bognar 3y ago
How far up the stack does the verification go? Most secure boot stacks give up after the initramfs because disk images are usually mutable. Do you make any attempts to go further?
- kfreds 3y ago> Do you make any attempts to go further? Yes. At the moment we're targeting x86-64 servers with UEFI. On such platforms we aim to do the following: 1. UEFI does measurement and verification of stboot using UEFI Secure Boot 2. stboot does measurement and verification of stvmm 3. stvmm does measurement and verification of Guest VMs 4. Clients use STAM to verify Guest VMs when establishing a secure connection * UEFI Secure Boot is 2048-bit RSA. * Measurements are done assuming the platform has a TPM. * stboot will do m/n signature verification for source release, reproducibility and build release, as well as verify Sigsum log inclusion. (Ed25519) * Sigsum log inclusion is just another detached signature blob, containing an inclusion proof, and signatures on that proof from the log operator and m/n cosigning witnesses. * stvmm will be Linux KVM + Firecracker, and an authenticated API for listing, starting and stopping VMs. * STAM is the System Transparency Authentication Mechanism. For more details, see my recent talk at OSFC, linked elsewhere in this thread. It's admittedly a bit all over the place.