New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider to install AEM as part of the standard installation #803

Open
marmarek opened this Issue Mar 8, 2015 · 1 comment

Comments

Projects
None yet
2 participants
@marmarek
Member

marmarek commented Mar 8, 2015

Reported by joanna on 12 Mar 2014 00:02 UTC

  • install AEM on the local /boot (on hdd, not on a separate stick). This makes sense only when SRK password is used.
  • Also, if the machine doesn't support TXT, then we should ensure grub2 doesn't break the static chain of trust (e.g. by loading and executing some modules without measuring them and extending PCRs with the measurements).
  • This should allow an easy way to also create AEM on a separate stick. This has some advantages, e.g. if TXT is not supported, and if grub2 is broken (SRTM-wise), then AEM on a separate stick makes still sense.

Migrated-From: https://wiki.qubes-os.org/ticket/803

@marmarek

This comment has been minimized.

Show comment
Hide comment
@marmarek

marmarek Mar 8, 2015

Member

Modified by joanna on 14 Mar 2014 12:55 UTC

Member

marmarek commented Mar 8, 2015

Modified by joanna on 14 Mar 2014 12:55 UTC

@marmarek marmarek modified the milestones: Release 3, Release 2 rc1 Mar 8, 2015

@marmarek marmarek modified the milestones: Release 3.1, Release 3.0 May 13, 2015

andrewdavidwong added a commit that referenced this issue Jun 9, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment