Tracking issue: Boot security in NixOS #265640
Labels
0.kind: enhancement
Add something new
2.status: work-in-progress
This PR isn't done
5. scope: tracking
Long-lived issue tracking long-term fixes or multiple sub-problems
6.topic: nixos
Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS
6.topic: systemd
significant
Novel ideas, large API changes, notable refactorings, issues with RFC potential, etc.
This is a tracking issue for work around Boot security in NixOS incorporating elements of https://github.com/nix-community/projects/blob/main/proposals/nixpkgs-security.md.
Upstream features
verify
algorithms nix-community/goblin-signing#3.initrd
via addons systemd/systemd#28070Work driven by @RaitoBezarius
UEFI Secure Boot by default for NixOS installer images
Work driven by @lheckemann, with the help of @mschwaig.
Bootspec v2
TPM2 in lanzaboote
Work driven by @RaitoBezarius
A/B schema in NixOS
Work driven by @JulienMalka
Integrity checks for the store
Work driven by @ElvishJerricco
Interpreter-less NixOS
Tracking issue: #267982
Design document: https://pad.lassul.us/nixos-perlless-activation#
Work driven by @nikstur, with the help of @blitz @lheckemann.
The text was updated successfully, but these errors were encountered: