{"repo":"nix-community/lanzaboote","free":true,"listed":false,"github":"https://github.com/nix-community/lanzaboote","clone":"git clone https://github.com/nix-community/lanzaboote.git","description":"Secure Boot & Measured Boot for NixOS [maintainers=@blitz @raitobezarius @nikstur]","language":"Rust","stars":1807,"topics":["efi","nix","nixos","nixpkgs","rust","security","uefi","measured-boot","secure-boot","tpm2"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Lanzaboote: Secure Boot & Measured Boot for NixOS This repository contains tooling for UEFI Secure Boot and Measured Boot on NixOS. Getting Started To start using Lanzaboote head to our docs! 🪛 Get Involved 🪛 Read the contributing guide to learn how to get involved. Overview Secure Boot The goal of UEFI Secure Boot is to allow only trusted operating systems to boot on a system. This can be used to defend against certain classes of attacks that compromise the boot flow of a system. For example, an attacker will have difficulty replacing the Linux kernel that boots a system when Secure Boot is active. UEFI Secure Boot works by digitally signing all drivers, bootloaders, the Linux kernel and its initrd. This establishes a chain of trust where one trusted component only hands off control to the next part of the boot flow when the integrity of the chain is cryptographically validated. Caveats There are some additional steps that are required to make UEFI Secure Boot effective: - There must be a BIOS password or a similar restriction that prevents unauthorized changes to the Secure Boot policy. - The booted system must have some form of integrity protection. - The firmware must be kept up-to-date. These steps will not be covered here. Measured Boot Measured Boot leverages measurements done by a TPM of all relevant boot components to bind the encryption of secrets (e.g. your LUKS volume key) to a security policy (i.e. expected measurements). This approach is compatible with Secure","default_branch":null,"files":null,"tree":[],"storefront":"/r/nix-community","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nix-community/lanzaboote/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}