Hi all,
We’re looking to harden our system using Orin NX, by extending the secure boot flow include verification of the rootfs as well.
We’re currently using a ext4 filesystem mounted read-only and secure boot up to and including the kernel and initramfs.
Does anyone have experience using dm-verity or similar approaches to ensure full root of trust all the way?
Or are there other better alternatives for Orin NX and meta-tegra?
Thanks!
Hi all,
We’re looking to harden our system using Orin NX, by extending the secure boot flow include verification of the rootfs as well.
We’re currently using a ext4 filesystem mounted read-only and secure boot up to and including the kernel and initramfs.
Does anyone have experience using dm-verity or similar approaches to ensure full root of trust all the way?
Or are there other better alternatives for Orin NX and meta-tegra?
Thanks!