Skip to content

Hardened/production builds cannot boot real HW: unsigned binary vs Secure Boot, TPM required #427

Description

@eKisNonos

Hardened/production builds cannot boot on real hardware as shipped, for two coupled reasons, and neither is documented.

Unsigned binary vs Secure Boot: the ISO/ESP build copies nonos_boot.efi straight to EFI/Boot/BOOTX64.EFI with no sbsign/pesign, no shim, no SBAT, no db.auth (mk/20-build.mk, mk/30-image.mk). But Hardened mode's enforce_secure_boot (security/enforce/requirements/secureboot.rs:22) denies and fatal_resets when firmware Secure Boot is OFF. So Hardened demands Secure Boot ON, yet the unsigned binary cannot pass firmware Secure Boot to start. The only path is enrolling the NONOS key into db (or a shim+MOK flow that does not exist). Ship a signing + cert-enrollment target, or document "Hardened requires key enrollment," or provide a shim+SBAT path.

TPM required but often off: Hardened's enforce_measured_boot denies when EFI_TCG2 is absent (modes/hardened.rs:31), and many consumer boards ship fTPM/PTT disabled by default. User must enable it in firmware.

Standard mode only warns on both, so the default standard-qemu image boots on real HW with Secure Boot and TPM merely warned. The real-HW blockers are concentrated entirely in the production/hardened policy. Also: the Hardened HW-RNG gate is RDRAND-only (requirements/hardware.rs:20) and should accept RDSEED too, so pre-Ivy-Bridge / some Atom CPUs are not excluded.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions