-
-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Path toward having a measurable dom0 #9146
Comments
If you're using grub with tpm support (#9165 ), then you would have measurement up to the initramfs. From there, you could have two boot options:
On a similar note, you could split the / of templates to be some overlay of a dm verity'd base /, signed by the upstream template provider, and a local changes lv that should be small, easy to reset and simpler to verify. |
I think are two different ways to use measured boot:
|
Torward measuring templates integrity between updates dom0 is now separated from vm-pool
Originally posted by @marmarek in linuxboot/heads#202 (comment)
But how to reach the goal of being able to measure dom0 from the bootloader?
PoC and original discussion https://groups.google.com/g/qubes-devel/c/hG93VcwWtRY
The text was updated successfully, but these errors were encountered: