Skip to content

Secure boot and verification of rootfs #2089

Description

@jsaf0

Hi all,

We’re looking to harden our system using Orin NX, by extending the secure boot flow include verification of the rootfs as well.

We’re currently using a ext4 filesystem mounted read-only and secure boot up to and including the kernel and initramfs.

Does anyone have experience using dm-verity or similar approaches to ensure full root of trust all the way?

Or are there other better alternatives for Orin NX and meta-tegra?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions