Re: [Tails-dev] [Tails-ux] TAILS Secure Boot Support

Delete this message

Reply to this message
Author: intrigeri
Date:  
To: Pavel Penev, The Tails public development discussion list
Subject: Re: [Tails-dev] [Tails-ux] TAILS Secure Boot Support
Hi,

sajolida:
> I'll let our developers have a look and see if such a technique could be
> implemented in Tails before Debian 10 (Buster) scheduled for mid-2019.


Thanks for caring.

This technique is basically what we're going to do when we add Secure
Boot support. In theory one could probably implement it this right
now. Having to use the signed shim and GRUB2 packages from Buster,
while we build in a Stretch environment, may make it a little bit more
challenging than waiting until Tails is based on Buster but I doubt
that would be a serious blocker. All in all, I suspect the hardest
part is not really the Secure Boot part, it's distributing an USB
image (#15292) and then migrating to GRUB2 (#15806).

So your question boils down to "can we do it earlier than planned?".
Our Foundations Team is plenty busy with other matters in 2018Q4 and
2019Q1. If the community thinks we should postpone some of this
planned work in order to tackle GRUB2 and Secure Boot earlier, please
let us know.

Now, if anyone else wants to work on this earlier, I'll be more than
happy to review your work :)

Cheers,
--
intrigeri