<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Immutable Debian systems using shim and systemd-boot</title>
        <link>https://peertube.debian.social/videos/watch/78b292f6-9d75-4ad6-973d-fc5667359b33</link>
        <description>by Tobias Deiminger At: MiniDebConf Winterthur 2026 https://ch2026.mini.debconf.org/talks/17-immutable-debian-systems-using-shim-and-systemd-boot/ Immutable systems are a state-of-the-art response to certain security threats for embedded systems. While secure boot only verifies the boot chain up to (and including) Linux, immutable systems additionally verify the integrity of the root file system (RFS) with all applications. A pattern using dm-verity was made popular in the embedded industry by related work from e.g. Jan Kiszka, Christian Storm [1][2] and Manuel Traut [3]. More recently, new specifications like shim SBAT and UKI add-ons have emerged, enabling a more maintainable workflow and new features: The dm-verity roothash can be deployed as a cmdline snippet in a separately signed UKI add-on. This decouples main UKI generation from roothash signing which allows for more maintainable CI-based signing workflow., SBAT can be used for rollback protection of boot components. Since the roothash is wrapped in a UKI add-on, this rollback protection can be extended to the whole RFS., Enrolling UEFI keys to the device during manufacturing process., swupdate integration of systemd-bless-boot to mark successful updates and trigger automatic rollback on failure., The talk demonstrates the setup of such a system from building it using the ELBE RFS build tool, pulling from Debian trixie, signing all parts, provisioning key material, updating to a new version and revoking a certain boot component version. It will be presented taking QEMU as an exemplary target system, but can be adapted to a broad range of real embedded targets thanks to UEFI or U-Boot's UEFI emulation on boards without native UEFI firmware. For production usage, signing locally is usually not an option. Therefore the talk also demonstrates how to reuse Debian's signing-templates workflow in manufacturer's CI outside Debian infrastructure using the small opensighub wrapper tool. ReferencesEmbedded Linux Conference 2022 – Implementing UEFI-based Secure Boot + OTA Update for Embedded ARM Devices, FOSDEM 2025 – Generating immutable, A/B updatable, securely booting Debian images, All Systems Go! 2024 – Booting an embedded system like a PC, Room: Campo Foyez (Main Track) Scheduled start: 2026-08-30 11:45:00+02:00</description>
        <lastBuildDate>Fri, 04 Sep 2026 21:27:31 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.debian.social</generator>
        <image>
            <title>Immutable Debian systems using shim and systemd-boot</title>
            <url>https://peertube.debian.social/client/assets/images/icons/icon-96x96.png</url>
            <link>https://peertube.debian.social/videos/watch/78b292f6-9d75-4ad6-973d-fc5667359b33</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.debian.social/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.debian.social/feeds/video-comments.xml?videoId=78b292f6-9d75-4ad6-973d-fc5667359b33" rel="self" type="application/rss+xml"/>
    </channel>
</rss>