Skip to content

Phase 4: AMD support for Qubes OS AEM with TrenchBoot

No due date 50% complete

This is Phase 4 for TrenchBoot as Anti Evil Maid project, as
outlined in the documentation: and https://docs.dasharo.com/projects/trenchboot-aem-v2/.
Phase 4 of the TrenchBoot AEM project aims to add support for AMD hardware with TrenchBoot on Qubes OS AEM. This phase consists of the following scope:

  1. Updating the Secure Kernel Loader package support for …

This is Phase 4 for TrenchBoot as Anti Evil Maid project, as
outlined in the documentation: and https://docs.dasharo.com/projects/trenchboot-aem-v2/.
Phase 4 of the TrenchBoot AEM project aims to add support for AMD hardware with TrenchBoot on Qubes OS AEM. This phase consists of the following scope:

  1. Updating the Secure Kernel Loader package support for Qubes OS AEM.
    Implementing TrenchBoot Secure Kernel Loader improvements for AMD server CPUs with multiple nodes.
  2. Updating TrenchBoot boot protocol for AMD in GRUB2.
  3. Updating TrenchBoot boot protocol for AMD in Secure Kernel Loader.
  4. Testing the solution on AMD hardware with TPM 2.0 and TPM 1.2 in legacy boot mode.