From: Ahmad Fatoum <[email protected]> So they can be referred to from the threat model chapter.
Signed-off-by: Ahmad Fatoum <[email protected]> --- Documentation/user/security.rst | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst index 185adac2d51c..1ad4fa905d54 100644 --- a/Documentation/user/security.rst +++ b/Documentation/user/security.rst @@ -84,6 +84,8 @@ devicetree from the previous stage. It's thus only suitable for verified boot if that stage verified the devicetree as well, e.g. because both are part of the same signed FIP image. +.. _loading_firmware: + Loading firmware ---------------- @@ -97,6 +99,8 @@ Firmware) should happen as early as possible, i.e., within the barebox barebox will run with elevated permission, which greatly increases the attack surface. +.. _pinning_fit_config: + Pinning the FIT configuration ----------------------------- @@ -138,6 +142,8 @@ development keys into the barebox binary. The private keys for these keys can be found `[here] <https://github.com/pengutronix/ptx-code-signing-dev>`__. +.. _disabling_shell: + Disabling the shell ^^^^^^^^^^^^^^^^^^^ @@ -157,6 +163,8 @@ that. Whoever reaches the shell is as trusted as the boot chain, so any remaining way of reaching it is part of the boot chain. A console kept for diagnostics should be output-only. +.. _disabling_env: + Disabling the non-builtin environment ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -185,6 +193,8 @@ way to arbitrarily set global variables, be it a writable environment, a script on media or a shell, defeats verified boot regardless of how well the images are signed. +.. _avoiding_filesystems: + Avoiding use of file systems ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -203,6 +213,8 @@ If file system use is desired anyway, its integrity should be ensured by other means, e.g. by being mounted from a dm-verity block device that was setup with a correctly signed root hash. +.. _verity_root_param: + Prevent the kernel from booting the rootfs in verity boots ---------------------------------------------------------- @@ -248,6 +260,8 @@ an attacker. It's thus strongly advisable to keep a separate secure configuration that disables all features that are used for development and are not absolutely necessary for booting in the field. +.. _runtime_configuration: + Run-time configuration ^^^^^^^^^^^^^^^^^^^^^^ -- 2.47.3
