Обложка канала

Qubes OS📢

904 @QubesOS

Get updates about QubeOS as soon as the announcements are released from the developers.

Qubes OS📢

4 года назад
Открыть в
Analogically to GRUB, Xen had to take over some responsibilities from tboot. Due to the Intel TXT requirements for the boot process, a new entry point had to be developed to which SINIT ACM will return control. The new entry point was responsible for saving information that a TXT launch happened and cleaning up the processor state so that the booting of the Xen kernel could continue with the standard Multiboot2 path. Among others, if Xen detected TXT launch, it had to perform the special processor cores wakeup process (which has been rewritten from TrenchBoot Linux patches to Xen native code) and measure external components before using them (that is the Xen parameters, Dom0 Linux kernel, initrd and Dom0 parameters). Xen also had to reserve the memory regions used by Intel TXT, as when tboot was used. The relevant source code for the respective Qubes Xen package is available here (https://github.com/3mdeb/qubes-vmm-xen/pull/1). Installation and verification of TrenchBoot AEM on Qubes OS For a seamless deployment and installation of TrenchBoot AEM, the modifications Qubes OS components compilation. Those patches have been presented earlier with have been converted to patches which are applied to projects’ sources during links to Pull Requests. It allows building ready-to-use RPM packages that can be installed directly on an installed Qubes OS system. The pre-built packages can be downloaded from here (3mdeb.com/open-so…_aem_poc). The packages have been covered with SHA512 sums signed with 3mdeb’s Qubes OS TrenchBoot AEM open-source software release 0.x signing key available on 3mdeb-secpack repository (github.com/3mdeb/3…-key.asc). To verify the RPM packages, fetch the key with the following command: gpg --fetch raw.githubusercontent.com/3mdeb/3…-key.asc and then to verify the packages, please run: $ gpg --verify sha512sums.sig sha512sums gpg: Signature made wto, 31 sty 2023, 11:06:06 CET gpg: using RSA key 3405D1E4509CD18A3EA762245D289020C07114F3 gpg: Good signature from "Qubes OS TrenchBoot AEM open-source software release 0.x signing key" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 3405 D1E4 509C D18A 3EA7 6224 5D28 9020 C071 14F3 $ sha512sum -c sha512sums grub2-common-2.06-1.fc32.noarch.rpm: OK grub2-tools-extra-2.06-1.fc32.x86_64.rpm: OK xen-licenses-4.17.0-3.fc32.x86_64.rpm: OK grub2-pc-2.06-1.fc32.x86_64.rpm: OK xen-libs-4.17.0-3.fc32.x86_64.rpm: OK grub2-tools-2.06-1.fc32.x86_64.rpm: OK xen-hypervisor-4.17.0-3.fc32.x86_64.rpm: OK grub2-pc-modules-2.06-1.fc32.noarch.rpm: OK xen-runtime-4.17.0-3.fc32.x86_64.rpm: OK grub2-tools-minimal-2.06-1.fc32.x86_64.rpm: OK python3-xen-4.17.0-3.fc32.x86_64.rpm: OK xen-4.17.0-3.fc32.x86_64.rpm: OK Check if GPG returns a good signature and if yes, check if the RPM checksum matches. All files must be in the same directory for the procedure to work. Note, in order to use the TrenchBoot AEM for Qubes OS, you have to own a TXT-capable platform with TXT-enabled firmware offering legacy boot. Such platform can be Dell OptiPlex 7010. You can visit Dasharo with Intel TXT support blog post (blog.3mdeb.com/2022/20…plex-txt) to learn more about such hardware and firmware. If you want to get OptiPlex with Dasharo pre-installed, you can get one from 3mdeb shop (3mdeb.com/shop/op…ram-copy). Building Xen and GRUB packages If you are not interested in compilation, skip to the next section (www.qubes-os.org…).