The first modern server platform based on CoreBoot has been introduced.

Developers from 9elements ported CoreBoot for the Supermicro server motherboard X11SSH-TF. The changes are already includes integrated into the main CoreBoot codebase and will be included in the next significant release. The Supermicro X11SSH-TF has become the first modern server motherboard with an Intel Xeon processor that can be used with CoreBoot. The board supports Xeon processors (E3-1200V6 Kabylake-S or E3-1200V5 Skylake-S) and can be equipped with up to 64 GB of RAM (4 x UDIMM DDR4 2400MHz).

The work was carried out in collaboration with VPN provider Mullvad as part of the System Transparencyproject aimed at enhancing the security of server infrastructure and eliminating proprietary components whose state cannot be controlled. CoreBoot is a free alternative to proprietary firmware and is available for full verification and auditing. CoreBoot serves as the base firmware for initializing hardware and coordinating the initial boot process. This includes the initialization of the graphics chip, PCIe, SATA, USB, RS232. Additionally, CoreBoot integrates binary components FSP 2.0 (Intel Firmware Support Package) and binary firmware for the Intel ME subsystem, necessary for the initialization and startup of the CPU and chipset.

For booting the operating system, it is recommended to use SeaBios or LinuxBoot (the UEFI implementation based on Tianocore is not yet supported due to incompatibility with the Aspeed NGI graphics subsystem, which operates only in text mode). In addition to adding board support to CoreBoot, project participants also implemented support for TPM (Trusted Platform Module) 1.2/2.0 modules based on Intel ME and prepared a driver for the ASPEED 2400 SuperI/O controller that performs BMC (Baseboard Management Controller) functions.

For remote management of the board, the operation of the IPMI interface provided by the BMC AST2400 controller is ensured, but to use IPMI, the original firmware must be installed in the BMC controller. Verified boot functionality has also been implemented. Support for AST2400 has been added to the superiotool , and support for Intel Xeon E3-1200 has been added to inteltool. Intel SGX (Software Guard Extensions) is still not supported due to stability issues.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster