Skip to content

Phase 3: Update to the newest TrenchBoot boot protocol

Closed Jan 17, 2024 100% complete

This is Phase 3 for TrenchBoot as Anti Evil Maid project, as
outlined in the documentation: and https://docs.dasharo.com/projects/trenchboot-aem-v2/.

This phase aims to update the TrenchBoot support in Qubes OS AEM to align with the newest TrenchBoot boot protocol upstreamed to Linux kernel and GRUB. This involves code rebasing onto the most recent work i…

This is Phase 3 for TrenchBoot as Anti Evil Maid project, as
outlined in the documentation: and https://docs.dasharo.com/projects/trenchboot-aem-v2/.

This phase aims to update the TrenchBoot support in Qubes OS AEM to align with the newest TrenchBoot boot protocol upstreamed to Linux kernel and GRUB. This involves code rebasing onto the most recent work implementing Secure Launch protocol and updating Xen to follow a similar approach as Linux kernel for DRTM launch. Testing the solution on Intel hardware with TPM 1.2 and TPM 2.0 using legacy boot mode is also a crucial aspect of this phase.

Loading