Trezor in Qubes

58 views
Skip to first unread message

taran1s

unread,
Aug 26, 2021, 10:28:00 AM8/26/21
to qubes-users
Hello all, I would like to start to use Trezor with my qubes. I would
like to follow this guide here https://wiki.trezor.io/Qubes_OS. My
intention is to use the Trezor HW wallet in a anon-whonix AppVm with
Trezor Suite qube through Tor. I run qubes on X230 Nitropad.

I would like to check if the guide to install the Trezor Bridge and Udev
rules in the sys-usb (see the official Trezor guide) is advised by qubes
community or is it good practice not to install anything in the sys-usb
and instead install the packages (bridge, udev rules and suite) in the
target anon-whonix AppVM.

tetra...@danwin1210.me

unread,
Aug 27, 2021, 8:08:38 AM8/27/21
to taran1s, qubes-users

taran1s

unread,
Aug 30, 2021, 7:03:04 AM8/30/21
to qubes-users

tetrahedra via qubes-users:
Thank you for the advice. You mention on github to verify the bridge,
but I cannot find any signed hash or anything for Trezor bridge and udev
rules. Can you point me to it?

taran1s

unread,
Sep 3, 2021, 3:55:18 AM9/3/21
to tetra...@danwin1210.me, qubes-users


tetra...@danwin1210.me:
Thank you for the guide. I tried to follow the official guide on trezor
wiki, abstaining from fedora a bit more, but still erroring.

To your guide. The last 4 lines:

copy to fedora-3x

in fedora-3x sudo rpm -i /path/to/trezor.rpm

...are to be done in the fedora-3x template, right? Will it work on
fedora-33-minimal too, or it needs to be full template?

All done, but I wasnt able to find any signed hash of the bridge or
something and so I get this error:

[user@fedora-33-min-trezor ~]$ sudo rpm -i trezor-bridge-2.0.27-1.x86_64.rpm
warning: trezor-bridge-2.0.27-1.x86_64.rpm: Header V4 RSA/SHA256
Signature, key ID b9a02a3d: NOKEY
package trezor-bridge-2.0.27-1.x86_64 does not verify: Header V4
RSA/SHA256 Signature, key ID b9a02a3d: NOKEY

tetra...@danwin1210.me

unread,
Sep 4, 2021, 5:05:39 PM9/4/21
to taran1s, qubes-users
On Fri, Sep 03, 2021 at 07:54:56AM +0000, taran1s wrote:
>Thank you for the guide. I tried to follow the official guide on
>trezor wiki, abstaining from fedora a bit more, but still erroring.
>
>To your guide. The last 4 lines:
>
>copy to fedora-3x
>
>in fedora-3x sudo rpm -i /path/to/trezor.rpm
>
>...are to be done in the fedora-3x template, right? Will it work on
>fedora-33-minimal too, or it needs to be full template?

I don't know.

>All done, but I wasnt able to find any signed hash of the bridge or
>something and so I get this error:
>
>[user@fedora-33-min-trezor ~]$ sudo rpm -i trezor-bridge-2.0.27-1.x86_64.rpm
>warning: trezor-bridge-2.0.27-1.x86_64.rpm: Header V4 RSA/SHA256
>Signature, key ID b9a02a3d: NOKEY
> package trezor-bridge-2.0.27-1.x86_64 does not verify: Header V4
>RSA/SHA256 Signature, key ID b9a02a3d: NOKEY

Weird. You have to install the Trezor verification key. I had to do this
the first time I installed, but after re-imaging my system, it wasn't
necessary on the most recent install, so I took the section out of my
notes. Unfortunately I don't remember what the steps were to install the
key!
Reply all
Reply to author
Forward
0 new messages