HCL - Dell Latitude E7440

402 views
Skip to first unread message

Bjarne Thomsen

unread,
Oct 25, 2014, 7:52:21 AM10/25/14
to qubes...@googlegroups.com
Both VT-x and VT-d are active.
There is only this problem:
TPM can only be enabled, if legacy BIOS is disabled and secure booting
is enabled.
How can I boot qubes with secure boot in UEFI?

Bjarne
Qubes-HCL-Dell_Inc.-Latitude_E7440-20141025-121839.txt

Marek Marczykowski-Górecki

unread,
Oct 25, 2014, 8:36:15 AM10/25/14
to Bjarne Thomsen, qubes...@googlegroups.com
Currently you can't:
https://wiki.qubes-os.org/ticket/794

--
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?

signature.asc

cprise

unread,
Oct 25, 2014, 12:50:52 PM10/25/14
to Bjarne Thomsen, qubes...@googlegroups.com
You should return the computer with a complaint; Restricting the TPM
like this is not normal.

Apparently, Dell thinks the only use for a TPM is the one Microsoft has
assigned to it.

cprise

unread,
Oct 25, 2014, 1:10:50 PM10/25/14
to Bjarne Thomsen, qubes...@googlegroups.com
Just remembered you had the Thinkpad-sans-VT-d earlier.... sorry to see
you are having such trouble getting a good Qubes laptop.

My approach would be to call Dell to see if there is a way around the
TPM restriction; Otherwise return the E7440 and get another T440p (or
T440, T440s or T540), making sure it has a fingerprint reader (easiest
way to tell it has a TPM) and choose a CPU for it that supports VT-d
(which you can check by looking up the CPU on the Intel ARK site).

bjarne....@gmail.com

unread,
Oct 26, 2014, 7:58:13 AM10/26/14
to qubes...@googlegroups.com, bjarne....@gmail.com

I do not think that UEFI is a bad idea. Adam Williamson has given a good
introduction to UEFI:
https://www.happyassassin.net/2014/01/25/uefi-boot-how-does-that-actually-work-then/
The problem is that the UEFI specifications do not give any guidelines on
how the firmware engineers should present the configuration to the user.

The goal for Qubes must be to be able to use a UEFI native boot.
The Dell E7440 came wit Windows 7 installed in BIOS compatibility mode, and
with a Windows 8 rescue CD. The only problem with ThinkPad T440p an Qubes R2 is that the mounted processor does not have VT-d. The TPM can be activated in legacy BIOS mode. I am going to buy a new processor with VT-d when the
prices have come down. But maybe Qubes R3 will be released before that happens?

bjarne....@gmail.com

unread,
Oct 26, 2014, 5:20:58 PM10/26/14
to qubes...@googlegroups.com, bjarne....@gmail.com

I have installed a Fedora20-Live (x86_64) DVD on the E7440 in UEFI mode.
It turned out that the TPM can be activated without the secure boot turned on.
I went through the installation description of the "Anti Evil Maid"
(without installing the qubes specific anti-evil-maid) by starting TrouSerS:
# systemctl start tcsd.service
followed by c) :
# find /sys/devices -name pcrs
# cat <path_to_pcrs>
PCR-00: xx xx xx etc.
so TPM is supported by the kernel.
Dell Latitude E7440 should be ready for qubes R3 (with UEFI support).

bjarne....@gmail.com

unread,
Nov 13, 2014, 9:52:50 AM11/13/14
to qubes...@googlegroups.com, bjarne....@gmail.com

I went a step further. I have managed to install Fedora-x86_64-21 beta in EFI
mode, so my Dell Latitude E7440 can now boot from disk with
UEFI boot enabled
TPM active
Secure Boot enabled
Trusted Execution enabled
BUT the 3.17.2 kernel does not detect TPM according to dmesg.
Does the kernel tpm module not work with UEFI firmware?

Bjarne

Reply all
Reply to author
Forward
0 new messages