osresearch / safeboot
Scripts to slightly improve the security of the Linux boot process with UEFI Secure Boot and TPM support
☆277Updated 2 years ago
Alternatives and similar repositories for safeboot:
Users that are interested in safeboot are comparing it to the libraries listed below
- Attest the trustworthiness of a device against a human using time-based one-time passwords☆173Updated 9 months ago
- Script to generate an OVMF vars file with default secure boot key enrolled.☆88Updated 2 years ago
- LinuxBoot book which contains the documentation in markdown format☆286Updated this week
- Mirror only. Official repository at https://git.glasklar.is/system-transparency/core/system-transparency☆86Updated last month
- DEPRECATED TPM enabled GRUB2 Bootloader☆194Updated 3 years ago
- A PKCS#11 interface for TPM2 hardware☆295Updated 2 weeks ago
- The libtpms library provides software emulation of a Trusted Platform Module (TPM 1.2 and TPM 2.0)☆232Updated 2 weeks ago
- Converged Security Suite for Intel & AMD platform security features☆60Updated last week
- A guide for setting up LUKS boot with a key from TPM in Linux☆183Updated 6 years ago
- Go-based tools for modifying UEFI firmware☆318Updated 3 months ago
- Paused mirror. Official repository at https://git.glasklar.is/system-transparency/core/stboot☆111Updated last year
- Framework to join Linux's physical security bricks.☆254Updated 3 weeks ago
- deprecated - maybe replaced by: `apparmor.d`☆84Updated last year
- Tools for using PIV tokens (like Yubikeys) as an SSH agent, for encrypting data at rest, and more☆200Updated last week
- ☆40Updated 4 months ago
- Linux UEFI library written in pure Go.☆148Updated 2 months ago
- TPM Genie is an I2C bus interposer for discrete Trusted Platform Modules☆213Updated 4 years ago
- Tools to let a u-root instance boot signed live distro images over the web☆109Updated 2 years ago
- Repository is intended to provide patches and rpm specs with experimental features to run under the Qubes OS.☆25Updated 4 years ago
- ☆164Updated last year
- Small and reliable initramfs solution supporting (remote) rescue shell, lvm, dmcrypt luks, software raid, tuxonice, uswsusp and more.☆317Updated last year
- Tutorials from TPM.dev members☆104Updated 9 months ago
- Linux Kernel Runtime Guard☆442Updated this week
- Kexecboot is a nice Linux-As-a-Bootloader implementation based on kexec☆113Updated last year
- TPM2 Access Broker & Resource Management Daemon implementing the TCG spec.☆119Updated 5 months ago
- A WebAuthn/U2F token protected by a TPM (Go/Linux)☆328Updated 11 months ago
- Display, extract, and manipulate PSP firmware inside UEFI images☆631Updated 5 months ago
- Reference implementation of the TCG Trusted Platform Module 2.0 specification.☆356Updated last month
- Calculate future (next boot) TPM PCRs after a kernel upgrade☆39Updated last year
- Firmware for the Nitrokey Pro device☆120Updated last year