BIOS check before Qubes installation

38 views
Skip to first unread message

Max

unread,
Jul 8, 2017, 12:40:31 PM7/8/17
to qubes...@googlegroups.com

Hello,
How to check if BIOS require digital signatures on BIOS firmware updates?

Chris Laprise

unread,
Jul 8, 2017, 3:17:27 PM7/8/17
to Max, qubes...@googlegroups.com
On 07/08/2017 12:16 PM, Max wrote:
> Hello,
> How to check if BIOS require digital signatures on BIOS firmware updates?
>

IIRC, a firmware setup menu that has an 'anti-rollback' protection
setting (to prevent earlier firmware versions from being accepted)
should have signature verification.

As of 2012 the UEFI spec did not require this feature. I believe this
has changed since then -- you can look for such a requirement at
http://www.uefi.org/specifications .

You will probably get a more definitive answer for this type of question
if you ask the Coreboot and Libreboot communities, as they regularly
deal with such protection measures.

--

Chris Laprise, tas...@openmailbox.org
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886
Reply all
Reply to author
Forward
0 new messages