Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nlnet past funded work placeholder for Authenticated Heads project (2022-2024) #1741

Closed
tlaurion opened this issue Aug 2, 2024 · 1 comment
Labels

Comments

@tlaurion
Copy link
Collaborator

tlaurion commented Aug 2, 2024

This is a placeholder for NLnet funded Authenticated Heads Project (2022-ongoing) to be able to refer here in its website (they can't change references per platform limitation) under website to be changed reference at https://nlnet.nl/project/AuthenticatedHeads/

Aka "Heads-OpenPGP"


A big thanks for NlNet to have trusted me managing the project through NGI Assure fund, once again, and to all direct and indirect participants


  • Travel expenses linked to FOSDEM 2023 conference - Heads - Status Update -> @tlaurion
  • QEMU targets to ease development/testing of Heads and debugging/tracing of what happens under the hood
  • TPM2 support under Heads -> @tlaurion (Big thanks to @JonathonHall-Purism for all the help!!!! Would not have happened without your collaboration.)
  • Authenticated Heads : in memory key generation, copy to USB Security dongle and preparation of USB Thumb drive to store keys securely, ask for SUB Security dongle/backup for signing/auth -> @tlaurion
  • Support platform locking (PR0) through SMI finalizing chipset - bring support to ivy/sandy/haswell platforms (Pre-Skylake: thanks @hardenedvault for initial PR!) -> @tlaurion
  • Reduce firmware footprint -> @tlaurion
  • Have flashrom support partial region Write Protection (Big thanks to @3mdeb @Dasharo - More specifically to @SergiiDmytruk @Pokisiekk @macpijan @krystian-hebel for the development and @pietrushnic for his trust
    • Have the coreboot bootblock set as read-only on the SPI flash
    • Have the flashrom deal properly with the write-protected bootblock region
  • Alternate build system investigation to better support reproducible builds (outcome: Nix based docker image builder) -> big thanks to @mmlb!!!! -> @tlaurion

Deliverables


Pending

  • Other tasks are still under grant work, to be edited when done
@tlaurion tlaurion changed the title Nlnet past funded work placeholder for Authenticated Heads project () Nlnet past funded work placeholder for Authenticated Heads project (2022-ongoing) Aug 2, 2024
@tlaurion tlaurion changed the title Nlnet past funded work placeholder for Authenticated Heads project (2022-ongoing) Nlnet past funded work placeholder for Authenticated Heads project (2022-2023) Sep 3, 2024
@tlaurion
Copy link
Collaborator Author

tlaurion commented Sep 3, 2024

NlNet "Assure" hard deadline was August 31 2024, which came unknowingly and abruptly for me attempting to do a Request for Payment yesterday.

Other work done will land when I have time to do it, but won't be considered funded. Sigh.

@tlaurion tlaurion closed this as completed Sep 3, 2024
@tlaurion tlaurion changed the title Nlnet past funded work placeholder for Authenticated Heads project (2022-2023) Nlnet past funded work placeholder for Authenticated Heads project (2022-2024) Sep 3, 2024
@tlaurion tlaurion added the grant label Nov 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant