heads/initrd/bin
Francis Lam 8004b5df2a
Added the ability to persist a default boot option
Similar to qubes-update, it will save then verify the hashes of
the kexec files. Once TOTP is verified, a normal boot will verify
that the file hashes and all the kexec params match and if
successful, boot directly to OS.

Also added a config option to require hash verification for
non-recovery boots, failing to recovery not met.
2017-07-04 19:49:14 -04:00
..
flashrom-x230.sh copy file and compute sha256 before flashing 2017-04-12 06:50:18 -04:00
generate-crypttab shell scripts to help rewrite Qubes initrd /etc/crypttab (issue #29) 2016-12-13 15:10:47 -05:00
gpgv Enable gpg with card support (issue #32) 2017-04-05 17:59:49 -04:00
kexec-boot Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
kexec-check-config Minor tweaks to signing params and boot options 2017-07-03 13:07:03 -04:00
kexec-iso-init Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
kexec-parse-boot Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
kexec-save-default Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
kexec-select-boot Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
kexec-sign-config Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
local-init Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
mount-usb move usb-storage into a kernel module (issue #160) 2017-04-05 19:20:53 -04:00
qubes-boot Rework /init and qubes setup scripts (issue #27, #155, #32, #29, #110) 2017-04-12 06:57:58 -04:00
qubes-init Rework /init and qubes setup scripts (issue #27, #155, #32, #29, #110) 2017-04-12 06:57:58 -04:00
qubes-install helper to install qubes from the recovery shell (issue #27) 2017-04-12 06:55:22 -04:00
qubes-measure-luks qubes init script and improved TPM disk encryption with LUKS headers (issue #123 and #6) 2017-04-01 23:02:00 -04:00
qubes-update Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
seal-key try creating NVRAM entry before prompting for owner password (issue #151) 2017-04-12 06:53:54 -04:00
seal-totp import the seal/unseal totp scripts since they are very specialized to the heads install, skip owner password if not required (issue #151) 2017-04-12 06:49:39 -04:00
start-xen formatting 2016-11-23 10:46:32 -05:00
tpm-reset helper to do a forcible TPM reset (issue #27) 2017-04-12 06:45:15 -04:00
unseal-key print and update the timestamp on the TOTP while waiting for disk unlock code 2017-04-12 08:28:31 -04:00
unseal-totp print and update the timestamp on the TOTP while waiting for disk unlock code 2017-04-12 08:28:31 -04:00
usb-init Minor tweaks to signing params and boot options 2017-07-03 13:07:03 -04:00
usb-scan Added the ability to persist a default boot option 2017-07-04 19:49:14 -04:00
wget-measure.sh wget and measure files into the PCR 2017-03-27 18:03:29 -04:00
wrap-cpio shell scripts to help rewrite Qubes initrd /etc/crypttab (issue #29) 2016-12-13 15:10:47 -05:00
x230-flash.init load usb-storage module in x230-flash.init 2017-04-16 17:37:14 -04:00