Developers from 9elements CoreBoot for the Supermicro server motherboard . The changes are already integrated into the main CoreBoot codebase and will be included in the next significant release. The Supermicro X11SSH-TF has become the first modern server motherboard with an Intel Xeon processor that can be used with CoreBoot. The board supports Xeon processors (E3-1200V6 Kabylake-S or E3-1200V5 Skylake-S) and can be equipped with up to 64 GB of RAM (4 x UDIMM DDR4 2400MHz).
The work was carried out with VPN provider Mullvad as part of the project aimed at enhancing the security of server infrastructure and eliminating proprietary components whose state cannot be controlled. CoreBoot is a free alternative to proprietary firmware and is available for full verification and auditing. CoreBoot serves as the base firmware for initializing hardware and coordinating the initial boot process. This includes the initialization of the graphics chip, PCIe, SATA, USB, RS232. Additionally, CoreBoot integrates binary components FSP 2.0 (Intel Firmware Support Package) and binary firmware for the Intel ME subsystem, necessary for the initialization and startup of the CPU and chipset.
For booting the operating system, it is recommended to use or (the UEFI implementation based on is not yet supported due to incompatibility with the Aspeed NGI graphics subsystem, which operates only in text mode). In addition to adding board support to CoreBoot, project participants also implemented support for TPM (Trusted Platform Module) 1.2/2.0 modules based on Intel ME and prepared a driver for the ASPEED 2400 SuperI/O controller that performs BMC (Baseboard Management Controller) functions.
For remote management of the board, the operation of the IPMI interface provided by the BMC AST2400 controller is ensured, but to use IPMI, the original firmware must be installed in the BMC controller. Verified boot functionality has also been implemented. Support for AST2400 has been added to the , and support for Intel Xeon E3-1200 has been added to Intel SGX (Software Guard Extensions) is still not supported due to stability issues.
Source: opennet.ru
