YoVDO

OpenPOWER Host OS Secure Boot Key Management

Offered By: Linux Foundation via YouTube

Tags

z/OS Courses Cryptography Courses Operating Systems Courses Computer Security Courses System Administration Courses Key Management Courses Secure Boot Courses Bootloaders Courses Firmware Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of OpenPOWER Host OS Secure Boot Key Management in this 33-minute conference talk by Nayna Jain from IBM. Dive into the open and flexible model for managing keys used by Linux-based bootloaders to verify and load the Host Operating System. Learn about the pluggable architecture supporting different key hierarchies and update mechanisms, as well as the options for vendors and sysadmins to manage OS installation in secure boot states. Discover the end-to-end solution spanning firmware, kernel, and userspace, including key ownership, authenticated updates, secure storage, blacklisting, and userspace tool compatibility. Gain insights into key management layers, internal processes, open-source key tools, flexible key authorities, and backend internals. Understand kernel verification flow, key destruction, rotation, error logs, and recovery procedures. Compare OpenPOWER's approach with existing secure boot key management mechanisms and explore its key takeaways for implementing robust security measures in Linux-based systems.

Syllabus

Intro
Acknowledgments
Open POWER Secure Boot
What is Key Management
Existing Mechanisms for Secure Boot Key Management
Key Management Layers
Key Management Intemals
Open Source Key Tools
Authorities over Key Management and Usage
Flexible Key Authorities
Backend Internals (Eric Richter)
Key Updates Processing
Protection of the Key Database - Storage & TSS
Kemel Verification
Kernel Verification Flow
Key Destruction
Key Rotation
Error Logs and Recovery
OpenPOWER Key Management - Key Takeaways
Revisiting Mechanisms for Secure Boot Key Management
References


Taught by

Linux Foundation

Tags

Related Courses

Architecting Applications for IBM Z and Cloud
IBM via Coursera
Architecting Applications for IBM Z and Cloud
IBM via edX
IBM Z App Modernization
IBM via edX
Introducing z/OS UNIX System Services
IBM via edX
Introduction to System Programming on IBM Z
IBM via edX