Re: Verified Boot, Secure Boot, dm-verity, debcheckroot

2019-11-16 Thread Elmar Stellnberger
There are tools that can help with checking all files on the hard drive such as `debsums`. However, while `debsums` is more popular, it is unsuitable. Quote https://www.elstel.org/debcheckroot/ ... During development of Verifiable Builds experiences were made with verification of MBR, VBR, bo

Re: Verified Boot, Secure Boot, dm-verity, debcheckroot

2019-11-16 Thread Sylvain Beucler
Hi, On 16/11/2019 15:22, Elmar Stellnberger wrote: > >> There are tools that can help with checking all files on the hard drive >> such as `debsums`. However, while `debsums` is more popular, it is >> unsuitable. >> >> Quote https://www.elstel.org/debcheckroot/ >> >> ... >> During development of V

Re: Verified Boot, Secure Boot, dm-verity, debcheckroot

2019-11-16 Thread Elmar Stellnberger
There are tools that can help with checking all files on the hard drive such as `debsums`. However, while `debsums` is more popular, it is unsuitable. Quote https://www.elstel.org/debcheckroot/ ... During development of Verifiable Builds experiences were made with verification of MBR, VBR, bo

Verified Boot, Secure Boot, dm-verity, debcheckroot

2019-11-16 Thread Patrick Schleizer
I am very interested in Verified Boot. Was wondering how it could be implemented on a Linux desktop distribution such as Debian. I would like to implement in Debian derivatives, that I maintain (Whonix, Kicksecure). Came up with some ideas which I will share here. https://www.whonix.org/wiki/Veri