<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Hardening Debian from UEFI to Userland, an example with LF Energy SEAPATH</title>
        <link>https://peertube.debian.social/videos/watch/2aa025c5-1a42-4e5e-a60f-0e6d0f03c72e</link>
        <description>by Eloi Bail by Mathieu Dupré At: DebConf25 https://debconf25.debconf.org/talks/174-hardening-debian-from-uefi-to-userland-an-example-with-lf-energy-seapath/ Mathieu and Eloi are the main contributors of LF Energy SEAPATH which use Debian as an VM hypervisor to host critical applications within Digital Substations. SEAPATH is used in production by RTE, the french electricity Transmission Service Operator (TSO). Because SEAPATH is used in a critical environment, cybersecurity hardening need to be deployed on top of Debian. This talk walks through the full system hardening process on Debian, starting with UEFI secure boot configuration and ending at service-level protections. We’ll cover secure bootloader (GRUB) configurations, encrypted and integrity-verified storage (dm-crypt, dm-verity), kernel hardening via command-line parameters, systemd service sandboxing, and general Debian-level hardening strategies. Attendees will gain actionable steps to improve the security posture of their Debian deployments, whether on laptops, servers, or embedded systems. Room: Méridienne Scheduled start: 2025-07-17 15:00:00+02:00</description>
        <lastBuildDate>Sat, 29 Aug 2026 07:49:56 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.debian.social</generator>
        <image>
            <title>Hardening Debian from UEFI to Userland, an example with LF Energy SEAPATH</title>
            <url>https://peertube.debian.social/client/assets/images/icons/icon-96x96.png</url>
            <link>https://peertube.debian.social/videos/watch/2aa025c5-1a42-4e5e-a60f-0e6d0f03c72e</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.debian.social/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.debian.social/feeds/video-comments.xml?videoId=2aa025c5-1a42-4e5e-a60f-0e6d0f03c72e" rel="self" type="application/rss+xml"/>
    </channel>
</rss>