Skip to content

Releases: osresearch/safeboot

Recovery signing, rollback protection, and less brittle PCRs

23 Aug 16:34
09da63b
Compare
Choose a tag to compare

image

Lots of improved features:

  • Added signed PCRs (#58)
  • Predict PCR4 and PCR2 based on sbsign --hash-only
  • Added TPM counters for rollback protection (#62)
  • TPM unsealing PINs (#5 )
  • safeboot.conf is now included in the initrd, fewer params on command line (#13 )
  • Recovery boot can now sign and hash root filesystem (#65)
  • Helpers for recovery boot to unlock cryptdisk, mount filesystems, etc (#56)
  • No more perl in /sbin/safeboot (#56)

shellchecked

20 May 21:19
Compare
Choose a tag to compare

Lots of documentation updates, some helpers for read-only mounts, and a few bugs caught by shellcheck.

sip-init works

11 May 16:08
b83a7ce
Compare
Choose a tag to compare

This one works all the way through on a fresh install, with instructions for doing sip-init to enable the read-only root filesystem and dmverity.

Works-for-me

10 May 21:57
Compare
Choose a tag to compare

Initial release, works for me on a fresh Ubuntu 20.04 install on a Thinkpad.