Boot from unsigned USB ISO: Change UX to propose to show iso hash for user first time validation + detach sign hashfile
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 1.6k
- Forks
- 211
- Avg merge
- 4d 21h
- Merged PRs (30d)
- 6
Description
We could have a "signing GUI" to sign an ISO with your key. Potentially this could also allow configuring which OS keys (if any) are trusted for ISO signatures, which integrates nicely with Restricted Boot.
Ideally, this should verify the ISO against sha256sums on the device while signing, or otherwise present the sha256 to the user for verification.
Original discussion: https://github.com/osresearch/heads/pull/1419#discussion_r1258631584
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No implementation file, test, or entry point is named. Start by reading the linked discussion in pull request 1419 and clarify the scope of signing, trusted OS keys, ISO verification, and detached hash files; done should be defined as an agreed UX and implementation plan.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100