Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking issue: Boot security in NixOS #265640

Open
RaitoBezarius opened this issue Nov 5, 2023 · 2 comments
Open

Tracking issue: Boot security in NixOS #265640

RaitoBezarius opened this issue Nov 5, 2023 · 2 comments
Labels
0.kind: enhancement 2.status: work-in-progress 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems 6.topic: nixos 6.topic: systemd significant Novel ideas, large API changes, notable refactorings, issues with RFC potential, etc.

Comments

@RaitoBezarius
Copy link
Member

RaitoBezarius commented Nov 5, 2023

This is a tracking issue for work around Boot security in NixOS incorporating elements of https://github.com/nix-community/projects/blob/main/proposals/nixpkgs-security.md.

Upstream features

Work driven by @RaitoBezarius

UEFI Secure Boot by default for NixOS installer images

Work driven by @lheckemann, with the help of @mschwaig.

Bootspec v2

TPM2 in lanzaboote

Work driven by @RaitoBezarius

A/B schema in NixOS

Work driven by @JulienMalka

Integrity checks for the store

Work driven by @ElvishJerricco

Interpreter-less NixOS

Tracking issue: #267982
Design document: https://pad.lassul.us/nixos-perlless-activation#

Work driven by @nikstur, with the help of @blitz @lheckemann.

@nixos-discourse
Copy link

This issue has been mentioned on NixOS Discourse. There might be relevant details there:

https://discourse.nixos.org/t/nixpkgs-supply-chain-security-project/34345/7

@infinisil infinisil added the significant Novel ideas, large API changes, notable refactorings, issues with RFC potential, etc. label Nov 19, 2023
@nikstur nikstur mentioned this issue Nov 28, 2023
13 tasks
@samueldr samueldr added the 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems label Apr 23, 2024
@AkechiShiro
Copy link
Contributor

The link to the proposal is broken, it seems it has become : https://github.com/nix-community/projects/blob/main/proposals/nixpkgs-security-phase2.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0.kind: enhancement 2.status: work-in-progress 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems 6.topic: nixos 6.topic: systemd significant Novel ideas, large API changes, notable refactorings, issues with RFC potential, etc.
Projects
None yet
Development

No branches or pull requests

5 participants