Re: AMD Secure Encrypted Virtualization - FreeBSD Status?

"Simon J. Gerraty via freebsd-virtualization" <[email protected]>
Newsgroups gmane.os.freebsd.devel.virtualization,gmane.os.freebsd.security.general,gmane.os.freebsd.current
Message-ID <[email protected]>
Tomasz CEDRO <[email protected]> wrote:

> would be really nice also to get UEFI BOOT compatible with SECURE BOOT :-)

Unless you are using your own BIOS, the above means getting Microsoft
to sign boot1.efi or similar. Shims that simply work around lack of
acceptible signature don't help.

That would need to then verify loader.efi - which can be built to
to verify all the modules and kernel.

In my implementation (uses the non efi loader) trust anchors are
embedded in loader but there is code in current to lookup trust anchors
in /efi I think which would be more generally useful - I've not looked
at the attack vectors that introduces though.

--sjg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.