linuxboot / linuxboot/heads

Boot from unsigned USB ISO: Change UX to propose to show iso hash for user first time validation + detach sign hashfile

Open
#1,438 11 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Makefile
Stars
1.6k
Forks
211
Avg merge
4d 21h
Merged PRs (30d)
6

Description

We could have a "signing GUI" to sign an ISO with your key. Potentially this could also allow configuring which OS keys (if any) are trusted for ISO signatures, which integrates nicely with Restricted Boot.

Ideally, this should verify the ISO against sha256sums on the device while signing, or otherwise present the sha256 to the user for verification.

Original discussion: https://github.com/osresearch/heads/pull/1419#discussion_r1258631584

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No implementation file, test, or entry point is named. Start by reading the linked discussion in pull request 1419 and clarify the scope of signing, trusted OS keys, ISO verification, and detached hash files; done should be defined as an agreed UX and implementation plan.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.