LinuxCon Europe UEFI Mini-Summit 7 October 2015

Similar documents
Strategies for Firmware Support of Self-Encrypting Drives

UEFI Spec Version 2.4 Facilitates Secure Update

UEFI Implications for Windows Server

Overview of Windows 10 Requirements for TPM, HVCI and SecureBoot

The UEFI Security Response Team (USRT)

UEFI on Dell BizClient Platforms

Trusted computing applied in Open Power Linux

UEFI Firmware Security Best Practices

ARM s role in Open Source software

Making UEFI Secure Boot Work With Open Platforms

SysPatrol - Server Security Monitor

Open Network Install Environment (ONIE) LinuxCon North America 2015

BitLocker Network Unlock & BitLocker support for Encrypted Drives

A White Paper By: Dr. Gaurav Banga SVP, Engineering & CTO, Phoenix Technologies. Bridging BIOS to UEFI

Providing a jump start to EFI application development and a uniform pre-boot environment

IBM Upward Integration Module (UIM) Advanced Technical Sales Wayne Wigley

Alliance Key Manager A Solution Brief for Technical Implementers

Dynamic Kernel Module Support. Matt Domsch, Software Architect Dell, Inc.

Build & Manage Clouds with Red Hat Cloud Infrastructure Products. TONI WILLBERG Solution Architect Red Hat toni@redhat.com

Building and Managing a Standard Operating Environment

OpenStack in the Enterprise: From Strategy to Real Life. Radhesh Balakrishnan General Manager OpenStack

Open Network Install Environment

SDN CENTRALIZED NETWORK COMMAND AND CONTROL

Integration and Automation with Lenovo XClarity Administrator

Race to bare metal: UEFI and hypervisors

FAQ. ImageCast 6 Frequently Asked Questions

EaseUS Todo Backup PXE Server

BitLocker Drive Encryption Hardware Enhanced Data Protection. Shon Eizenhoefer, Program Manager Microsoft Corporation

UEFI PXE Boot Performance Analysis

Technical Brief Distributed Trusted Computing

Windows Server on WAAS: Reduce Branch-Office Cost and Complexity with WAN Optimization and Secure, Reliable Local IT Services

Session ID: Session Classification:

This is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT.

ARM mbed IoT Device Platform. November 3 rd, 2014

Comprehensive Security for Internet-of-Things Devices With ARM TrustZone

Quo vadis Linux File Systems: An operations point of view on EXT4 and BTRFS. Udo Seidel

Hi and welcome to the Microsoft Virtual Academy and

CrashPlan PRO Enterprise Backup

Creating a More Secure Device with Windows Embedded Compact 7. Douglas Boling Boling Consulting Inc.

One-Stop Intel TXT Activation Guide

Oracle Linux Strategy and Roadmap

Satish Mohan. Head Engineering. AMD Developer Conference, Bangalore

MBR and EFI Disk Partition Systems

Windows Phone 8 Security deep dive

UEFI Development in HP

The Red Hat Enterprise Linux advantages over Oracle Linux


About Us. Technology Solutions & Services Company. Turn Innovative Ideas into Real Products & Software, Efficiently

Group-Based Policy for OpenStack

What s new in Hyper-V 2012 R2

Do Containers fully 'contain' security issues? A closer look at Docker and Warden. By Farshad Abasi,

Update for DIP-2040EZ-00N, DIP-2042EZ-4HD and DIP-2042EZ-2HD

ARE YOU RUNING LINUX RIGHT?

OPEN CLOUD INFRASTRUCTURE BUILT FOR THE ENTERPRISE

Microsoft Azure IaaS: Virtual Machine e Open Source interoperability

PowerVC 1.2 Q Power Systems Virtualization Center

OPENFLOW, SDN, OPEN SOURCE AND BARE METAL SWITCHES. Guido Appenzeller (Not representing Anyone)

HP Notebook Hard Drives & Solid State Drives. Identifying, Preventing, Diagnosing and Recovering from Drive Failures. Care and Maintenance Measures

Linux Distributions. What they are, how they work, which one to choose Avi Alkalay

Achieve Automated, End-to-End Firmware Management with Cisco UCS Manager

IT6204 Systems & Network Administration. (Optional)

The Fastest Path to the Cloud Building Your SaaS Company on Force.com

Cloud Technology Platform Enables Leading HR and Payroll Services Provider To Meet Solution Objectives

OF 1.3 Testing and Challenges

Security Security by Separation

Open Network Linux. A Path to an Open Source Network OS. Rob Sherwood Big Switch Networks CTO

Cisco and Red Hat: Application Centric Infrastructure Integration with OpenStack

Deployment Topologies - DPAdmin An isoagroup Product

Windows Hardware Certification Requirements

Cloud-Based dwaf A Real World Deployment Case Study. OWASP 5. April The OWASP Foundation

THE REVOLUTION TOWARDS SOFTWARE- DEFINED NETWORKING

Navigating Endpoint Encryption Technologies

YOUR STRATEGIC VIRTUALIZATION ALTERNATIVE. Greg Lissy Director, Red Hat Virtualization Business. James Rankin Senior Solutions Architect

Choices for implementing SMB 3 on non Windows Servers Dilip Naik HvNAS Pty Ltd Australians good at NAS protocols!

Cautions When Using BitLocker Drive Encryption on PRIMERGY

installing UEFi-based Microsoft Windows Vista SP1 (x64) on HP EliteBook and Compaq Notebook PCs

Active Directory - User, group, and computer account management in active directory on a domain controller. - User and group access and permissions.

HP OO 10.X - SiteScope Monitoring Templates

Practical Guide to Platform as a Service.

Migrating to the Cloud. Developing the right Cloud strategy and minimising migration risk with Logicalis Cloud Services

Cloud Security:Threats & Mitgations

Migration and Building of Data Centers in IBM SoftLayer with the RackWare Management Module

ios Security Decoded Dave Test Classroom and Lab Computing Penn State ITS Feedback -

Hybrid Platform Application in Software Debug

Radia Cloud. User Guide. For the Windows operating systems Software Version: Document Release Date: June 2014

DELL. Unified Server Configurator Security Overview. A Dell Technical White Paper. By Raja Tamilarasan, Wayne Liles, Marshal Savage and Weijia Zhang

Open Source Backup with Amanda

Edit system files. Delete file. ObserveIT Highlights. Change OS settings. Change password. See exactly what users are doing!

2013 Enterprise End User Report

Transcription:

LinuxCon Europe UEFI Mini-Summit 7 October 2015 Session 2 What Linux Developers Need to Know About Recent UEFI Spec Advances Jeff Bobzin, Insyde Software Corp.

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 2

UEFI Content Builds From Wide Industry Participation Cloud Operators The UEFI Committee Agenda is Driven by Community Input User Community OS Vendors Silicon Suppliers OEMs IBV IHV ISV UEFI UEFI SPECS UEFI SPECS SPECS Enterprise www.uefi.org 3

Some Messages UEFI Heard From The Ecosystem 1. PXE Boot too slow and unreliable 2. Field provisioning of Secure Boot security keys was awkward 3. Manual matching of firmware updates was too hard 4. UEFI did not support ISV needs for pre-os tools like disk encryption www.uefi.org 4

UEFI ECR Process Problem Statement Member Contribution Topic Experts From Member Companies UEFI Forum sub-teams include: Security, Network, Configuration, ARM, Shell and Video Sub Team Proposal for Spec Change Full Committee Review www.uefi.org 5

Spec Approval Process Approved ECRs Revised Spec with New Content Merged Approval By UEFI Board and Membership Review Publication! www.uefi.org 6

After Publication New Spec New Spec 2.5 Self-Certification Test Suite Implementation Teams Open Source Reference Implementation Spec 2.5a Update Revised w/ Errata www.uefi.org 7

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 8

Deeper Review Of 3 Important New Elements 1. [New] Section 22.3, EFI System Resource Table 2. [New] Section 30.3.x Audit Mode and Deployed Mode 3. [New] Section 3.1.7 System Prep Applications In Upcoming Session: 4. [New] Section 23.7.1 Boot from URL www.uefi.org 9

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 10

Enable System To Advertise Updatable Firmware UEFI 2.5 has added ESRT table List of Firmware Elements Identified by GUID and Version Status of last update Expansion Boards are added to ESRT by platform and updated by Firmware Management Protocol www.uefi.org 11

ESRT Allows Automation OS Checks Firmware Versions, Schedules Updates Update Server ESRT UEFI Firmware Updates Expansion Cards Local Devices www.uefi.org 12

Advantages Of ESRT-based Firmware Management 1. Move away from older proprietary schemes which require user learning for each platform or expansion board / vendor 2. OS able to easily confirm that correct (latest) versions are installed 3. Increased update participation will help to more quickly close any security flaws www.uefi.org 13

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 14

Security Profile Management Secure Boot and its database of signing keys can protect every boot step System Firmware SIGNED BY MOK KEY Checks Pre-Loader Checks MOK Linux Loader Checks Linux Kernel/ Drivers www.uefi.org 15

Provisioning Local Signing Some sites use local signing. Until UEFI 2.5, local key provisioning was a manual process with non-std. menus Hands on steps added greatly to the workload of setting up new server UEFI 2.5 adds new Audit and Deployed modes (these modes are security enforcement states) www.uefi.org 16

Using Audit and Deployed Modes Audit Mode OS can update security signing key lists and test the revised boot chain Unbootable state is avoided Deployed Mode Entered with OS is satisfied with key list Most Secure Mode www.uefi.org 17

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 18

System Prep Applications Problems we are solving: 1. Enable ISV Software that needs to run before OS to unlock encrypted disk (client and server) 2. Enable Firmware Version monitor/update when multiple OS are supported (enterprise/data center) 3. Pre-OS provisioning due to changing work-loads (data center) Why change was needed - Avoid war with OS over BootOrder OS always fights to be first www.uefi.org 19

Boot Timeline UEFI Phase HW Init (by System FW) SysPrep#1 SysPrep#2 OS UEFI Bootloader Success Boot Failure OS Recovery www.uefi.org 20

Sys Resources Available System Prep can use same system resources as OS bootloader Screen, Kbd, etc. Network If a required device is not normally initialized by fast boot a new API is provided to request device be made operational for the App to use www.uefi.org 21

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 22

UEFI 2.5 Partial Feature List Implementation Status UEFI 2.5 Item Boot from http (details session 4) Open Source Sys Firmware In final test OS Support Ready to engage with OS teams Boot from https Scheduled Currently in review/plan ESRT Firmware Table Security Profile Audit Mode System Prep Applications In final test, early versions shipping To be Scheduled In final test Linux* & Windows have support, distribution path from OEM needs work Time to review/plan Ready to engage * https://github.com/vathpela/linux-esrt www.uefi.org 23

Development System Purchase at www.tunnelmountain.net ($1399) Note: UEFI 2.5 binary is not yet posted, still in test www.uefi.org 24

Agenda Overview - The UEFI Process Some UEFI 2.5 Spec Highlights System Firmware Versions Published Security Profile Management at the Data Center System Prep Applications Progress To Date Call to Action www.uefi.org 25

We have heard from our user community, especially data center operators, about the improvements they need to streamline their operations. UEFI firmware is a good foundation for solutions, but only a foundation. Requires: Cooperative and interactive development effort from IBVs, OEMs, distros, IHVs and... Feedback from the original requestors. Let s figure out how to work together! www.uefi.org 26

Interested In Joining? www.uefi.org/membership UEFI FW/OS Forum: uefi.org/fwosforum A free public forum focused on firmware and O/S integration USRT Security Issue Reporting: uefi.org/security A safe reporting site to inform the UEFI of any security issue or vulnerability based on firmware