Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure boot support #81

Closed
andreldmonteiro opened this issue Oct 5, 2020 · 6 comments
Closed

Secure boot support #81

andreldmonteiro opened this issue Oct 5, 2020 · 6 comments
Labels
support Community support

Comments

@andreldmonteiro
Copy link

andreldmonteiro commented Oct 5, 2020

This issue is to request the support for secure boot in OPNsense to increase security in the OS.

I have tried OPNsense via the vga USB install image with GPT and UEFI boot and it doesn't boot when secure boot is enabled nor does OPNsense boot after it is installed and secure boot turned on only after installation is finished.

I don't believe HardenedBSD or FreeBSD currently fully support secure boot but I have not tested them, only OPNsense vga USB install image with GPT and UEFI boot support, so this bug pertains to OPNsense images.

@fichtner
Copy link
Member

fichtner commented Oct 5, 2020

You will have to clarify if this pertains to images of OPNsense, HardenedBSD, FreeBSD or BSD in general. Otherwise we won’t have a clear description. I also suspect a lot of potential requests are completely out of scope from the OPNsense project perspective.

@fichtner fichtner added the support Community support label Oct 5, 2020
@andreldmonteiro
Copy link
Author

I have tried and OPNsense doesn't boot when secure boot is enabled on the device, also I didn't find anything on a quick search on the documentation about it, I had a look and FreeBSD currently doesn't seem to support secure boot fully (https://wiki.freebsd.org/SecureBoot)
I think this is a must have feature to further enhance the OS.

@fichtner
Copy link
Member

fichtner commented Oct 5, 2020

I'm only asking once more for your clarification. Since you tried it and not all images support UEFI this is still missing key information.

@andreldmonteiro
Copy link
Author

I have edited the main bug and hope it has enough clarification now.

@fichtner
Copy link
Member

We have added UEFI to the serial image while it already existed for vga and dvd. That's as far as we can go for now unless there is more movement in FreeBSD (which I guess there will not be).

@andreldmonteiro
Copy link
Author

andreldmonteiro commented Jan 21, 2021

Based on the freebsd secure boot status page isn't it implemented up until the bootloader? So could it be implemented now up to the bootloader and stop verification after that, this would allow opnsense to boot and install with secure boot on and leave it enabled and the rest of the hardening could be done later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
support Community support
Development

No branches or pull requests

2 participants