Secure Boot?

indivision

Guru
Joined
Jan 4, 2013
Messages
806

joshenders

Cadet
Joined
Jan 3, 2022
Messages
2
Seems like this is still an issue even under the release version on Linux, TrueNAS-SCALE-22.02.0. I also wonder if this is planned. I'll follow up on the Jira project.
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
In the meantime, I’ve purchased an expensive paperweight because the AMI Bios version 1620 on ASUS board doesn’t allow me to deactivate SecureBoot
Maybe you can get away with a third party boot manager at least in the interim.

something like mixing these 2:


 

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
Thank you @sretalla for the pointers.

I've read the documentation and the process is quite complex:

1) I need to download the source code of shim and compile with some options...
2) I need to create my own keys to sign executables
3) I need to sign the existing boot of truenas? and loaded modules?

And test in loop to fix issues.

I could do a try, but only if I've support from iXsystems as I'm not aware of the details of how FreeBSD actually boots for TrueNAS (and it looks like FreeBSD does not support SecureBoot on its own) so,

Please iXsystems, if let me know if you can give me support on this process somehow!

Regards
Ignacio
 

Whattteva

Wizard
Joined
Mar 5, 2013
Messages
1,824
I could do a try, but only if I've support from iXsystems as I'm not aware of the details of how FreeBSD actually boots for TrueNAS (and it looks like FreeBSD does not support SecureBoot on its own) so,

Please iXsystems, if let me know if you can give me support on this process somehow!
You expect active support when you didn't even buy their hardware? You're a funny comedian, you.
 

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
Well, I'm NOT requesting support on their product (which is what they sell)
I'm requesting support on how the boot process works only in case I've problems with it.
ALSO note I'm providing them the experience as advanced user to implement a solution so their OS can be installed on MODERN HARDWARE that does not allows to disable secureboot (most of the new motherboards does not allow to disable SecureBoot)

Yes, I'll spend my time on the benefit of iXsystems and I want them to be involved in the process. It is a WIN WIN deal!
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
3) I need to sign the existing boot of truenas? and loaded modules?
I don't think that's how it would work...

I had posted the links with the intention that you come to be able to secure boot to Clover (a boot manager).

Clover would then (possibly) be able to boot TrueNAS without requiring TrueNAS itself to support secure boot.

Frankly, you've got a much better chance dealing with ASUS to get them to release a BIOS version that allows secure boot to be disabled.
 

Whattteva

Wizard
Joined
Mar 5, 2013
Messages
1,824
You're a funny guy, framing it as you're more doing them a favor than the other way around. They designed the product for enterprise users and probably have no interest running it on your Asus so-called "MODERN consumer HARDWARE". It just so happens they let you download it for free and run it on whatever hardware you want, but expecting them to personally come help you and then frame it as you doing them a favor is really a funny one.

If you want to actually be helpful, file a bug report. Not by demanding them to help you claiming it's a "WIN WIN deal" as if you're saving them millions.
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
I’ve purchased an expensive paperweight
There's a reason we have a hardware recommendations guide.

I don't think your request is all that unreasonable, in that I expect we're going to start seeing secure boot mandated by more and more hardware. I don't know that iX will be able to do much if the underlying OSs don't support it though.
 
Joined
Jan 18, 2017
Messages
525

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
If you want to actually be helpful, file a bug report.
Perhaps you didn't notice that he already did.

As to whether it's a win-win, I guess that depends on how likely you think it is that mandatory secure boot is going to make its way to server hardware in the near term.
 

Whattteva

Wizard
Joined
Mar 5, 2013
Messages
1,824
Perhaps you didn't notice that he already did.
Ah, my apologies. I missed that part. That still doesn't change the fact that the expectation for that kind of support beyond the forums community support without having a service contract is at least a bit interesting, especially given the framing.
 

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
I don't think that's how it would work...

I had posted the links with the intention that you come to be able to secure boot to Clover (a boot manager).

Frankly, you've got a much better chance dealing with ASUS to get them to release a BIOS version that allows secure boot to be disabled.

I’ll give Clover a try. Thanks.

Regarding ASUS. They are informed and I’m waiting for a response from their 2nd level support
 

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
You're a funny guy, framing it as you're more doing them a favor than the other way around. They designed the product for enterprise users and probably have no interest running it on your Asus so-called "MODERN consumer HARDWARE". It just so happens they let you download it for free and run it on whatever hardware you want, but expecting them to personally come help you and then frame it as you doing them a favor is really a funny one.

If you want to actually be helpful, file a bug report. Not by demanding them to help you claiming it's a "WIN WIN deal" as if you're saving them millions.

The BUG report was filled a week ago.
 

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
Thank you everyone for your responses. I really hope I could find a solution. Either, FreeBSD supports SecureBOOT and TrueNAS follows or the next version of TrueNAS could be based on Debian (as Proxmox is and it works)
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
or the next version of TrueNAS could be based on Debian
That's called TrueNAS SCALE, and it already exists.
 
  • Like
Reactions: ihr

Whattteva

Wizard
Joined
Mar 5, 2013
Messages
1,824
Thank you everyone for your responses. I really hope I could find a solution. Either, FreeBSD supports SecureBOOT and TrueNAS follows or the next version of TrueNAS could be based on Debian (as Proxmox is and it works)
TrueNAS SCALE is it. Just like Proxmox, it's Debian-based and using Linux kernel 5.15.79.
 
Last edited:
  • Like
Reactions: ihr

ihr

Dabbler
Joined
Jan 3, 2023
Messages
22
I'll take a look at TrueNAS SCALE! and come back. Thank you for the pointer!
 
Top