linuxboot / heads-wiki

Documentation for the Heads firmware project
85 stars 44 forks source link

Modify misleading ACM doc section of the wiki #95

Closed tlaurion closed 2 years ago

tlaurion commented 2 years ago

https://matrix.to/#/!pAlHOfxQNPXOgFGTmo:matrix.org/$UAIdfkhhtYR47KGUz0bN-rnN6RmKmsAHLS-8ajHqF2k?via=matrix.org&via=nitro.chat&via=fairydust.space

https://osresearch.net/Keys/#management-engine-and-bootguard-acm-fuses states:

The x230 Thinkpads do not support bootguard and only the Librem laptops ship with unfused keys.

This misleading and untrue.

Reality is that no such documentation existed at the moment of writing that page, and lack of personal interest didn't lead me to them.

But that could change with community contributions, with boards that of course would not be CI built, and without roms being redistributable, unless proven otherwise.

tlaurion commented 2 years ago

The x230 Thinkpads do not support bootguard and only the Librem laptops ship with unfused keys.

Is actually true.

Broadwell and up support TXT for SRTM (IBB measurement into PCR0 from BIOS ACM).

So the T440p being Haswell could have SRTM following blob extraction from CI, and Ivy and Haswell could have TXT, enabled by Sinit and BIOS ACMs.