How To Install tboot on Fedora 34

tboot is Performs a verified launch using Intel TXT

Introduction

In this tutorial we learn how to install tboot on Fedora 34.

What is tboot

Trusted Boot (tboot) is an open source, pre-kernel/VMM module that uses Intel Trusted Execution Technology (Intel TXT) to perform a measured and verified launch of an OS kernel/VMM.

We can use yum or dnf to install tboot on Fedora 34. In this tutorial we discuss both methods but you only need to choose one of method to install tboot.

Install tboot on Fedora 34 Using dnf

Update yum database with dnf using the following command.

sudo dnf makecache --refresh

The output should look something like this:

Fedora 34 - x86_64                               20 kB/s | 6.6 kB     00:00
Fedora 34 openh264 (From Cisco) - x86_64        1.4 kB/s | 989  B     00:00
Fedora Modular 34 - x86_64                       68 kB/s | 6.5 kB     00:00
Fedora 34 - x86_64 - Updates                    3.5 kB/s | 6.2 kB     00:01
Fedora Modular 34 - x86_64 - Updates             17 kB/s | 5.9 kB     00:00
Metadata cache created.

After updating yum database, We can install tboot using dnf by running the following command:

sudo dnf -y install tboot

Install tboot on Fedora 34 Using yum

Update yum database with yum using the following command.

sudo yum makecache --refresh

The output should look something like this:

Fedora 34 - x86_64                               20 kB/s | 6.6 kB     00:00
Fedora 34 openh264 (From Cisco) - x86_64        1.4 kB/s | 989  B     00:00
Fedora Modular 34 - x86_64                       68 kB/s | 6.5 kB     00:00
Fedora 34 - x86_64 - Updates                    3.5 kB/s | 6.2 kB     00:01
Fedora Modular 34 - x86_64 - Updates             17 kB/s | 5.9 kB     00:00
Metadata cache created.

After updating yum database, We can install tboot using yum by running the following command:

sudo yum -y install tboot

How To Uninstall tboot on Fedora 34

To uninstall only the tboot package we can use the following command:

sudo dnf remove tboot

tboot Package Contents on Fedora 34

/boot/tboot-syms
/boot/tboot.gz
/etc/grub.d/20_linux_tboot
/etc/grub.d/20_linux_xen_tboot
/usr/lib/.build-id
/usr/lib/.build-id/01
/usr/lib/.build-id/01/28847eb6df16588be999e1100796b0adaacd89
/usr/lib/.build-id/2d
/usr/lib/.build-id/2d/c4369f834d62871910ee32855c5d6438cc46be
/usr/lib/.build-id/41
/usr/lib/.build-id/41/5e12dcb0cbc01e3d2b0bd0cf828be9a3e8c16d
/usr/lib/.build-id/58
/usr/lib/.build-id/58/ec052eb21f847b595356329dd1dbf71bd8996d
/usr/lib/.build-id/5b
/usr/lib/.build-id/5b/e2cbc61fad64009ed83d6c1578662e09601849
/usr/lib/.build-id/68
/usr/lib/.build-id/68/3b3b08df825756fc75664871fc95d1895425e2
/usr/lib/.build-id/76
/usr/lib/.build-id/76/f8c45bee09ad575f62d1d7e640d6bc10c31a58
/usr/lib/.build-id/e1
/usr/lib/.build-id/e1/1ce69e0e41a2df6b3797b3f26d007a42d02cd2
/usr/sbin/lcp2_crtpol
/usr/sbin/lcp2_crtpolelt
/usr/sbin/lcp2_crtpollist
/usr/sbin/lcp2_mlehash
/usr/sbin/tb_polgen
/usr/sbin/txt-acminfo
/usr/sbin/txt-parse_err
/usr/sbin/txt-stat
/usr/share/doc/tboot
/usr/share/doc/tboot/COPYING
/usr/share/doc/tboot/Makefile
/usr/share/doc/tboot/howto_use.md
/usr/share/doc/tboot/man
/usr/share/doc/tboot/man/lcp2_crtpol.8
/usr/share/doc/tboot/man/lcp2_crtpolelt.8
/usr/share/doc/tboot/man/lcp2_crtpollist.8
/usr/share/doc/tboot/man/lcp2_mlehash.8
/usr/share/doc/tboot/man/tb_polgen.8
/usr/share/doc/tboot/man/txt-acminfo.8
/usr/share/doc/tboot/man/txt-parse_err.8
/usr/share/doc/tboot/man/txt-stat.8
/usr/share/doc/tboot/policy_v1.txt
/usr/share/doc/tboot/policy_v2.txt
/usr/share/doc/tboot/tboot_flow.md
/usr/share/doc/tboot/txt-info.txt
/usr/share/doc/tboot/vlp.txt
/usr/share/man/man8/lcp2_crtpol.8.gz
/usr/share/man/man8/lcp2_crtpolelt.8.gz
/usr/share/man/man8/lcp2_crtpollist.8.gz
/usr/share/man/man8/lcp2_mlehash.8.gz
/usr/share/man/man8/tb_polgen.8.gz
/usr/share/man/man8/txt-acminfo.8.gz
/usr/share/man/man8/txt-parse_err.8.gz
/usr/share/man/man8/txt-stat.8.gz
/boot/tboot-syms
/boot/tboot.gz
/etc/grub.d/20_linux_tboot
/etc/grub.d/20_linux_xen_tboot
/usr/lib/.build-id
/usr/lib/.build-id/0c
/usr/lib/.build-id/0c/d5374faf37332f18ac3698ce83a02796c65b91
/usr/lib/.build-id/18
/usr/lib/.build-id/18/a1540e48acf93589300abac85dfd7d06d33672
/usr/lib/.build-id/2b
/usr/lib/.build-id/2b/9f900f3dc34f62f18391d62ccab31d9a558709
/usr/lib/.build-id/38
/usr/lib/.build-id/38/1d7a98cb5018be1f4781e98eef44c3ea073ba8
/usr/lib/.build-id/39
/usr/lib/.build-id/39/a877d235a9afd610306b8336e6279c854edc74
/usr/lib/.build-id/3b
/usr/lib/.build-id/3b/00bad0ebacd9d257aab3e49ab3b04fd520dcf5
/usr/lib/.build-id/49
/usr/lib/.build-id/49/4df510986dca37872d1493bd0d41dd89b76fb8
/usr/lib/.build-id/60
/usr/lib/.build-id/60/f417410ca176f5b21eb8b7781af90a3cb0f9f6
/usr/lib/.build-id/78
/usr/lib/.build-id/78/e93cbff0fe1ede2acf61e59fddeef2007d9e66
/usr/lib/.build-id/89
/usr/lib/.build-id/89/daba2e9c47943039a9b4235e0d3a460dc1c83e
/usr/lib/.build-id/b5
/usr/lib/.build-id/b5/a8cd73444b7d16fcf041275c15e7451c9703ec
/usr/lib/.build-id/ce
/usr/lib/.build-id/ce/aa172ce994ac78a7805e425403eb809ee467d2
/usr/lib/.build-id/e2
/usr/lib/.build-id/e2/e22b8f2239fb5a7066ece1b6ba043ea5562464
/usr/lib/.build-id/fd
/usr/lib/.build-id/fd/97d179f28a5a997a87e29007ebc58595e97862
/usr/sbin/acminfo
/usr/sbin/lcp2_crtpol
/usr/sbin/lcp2_crtpolelt
/usr/sbin/lcp2_crtpollist
/usr/sbin/lcp2_mlehash
/usr/sbin/lcp_readpol
/usr/sbin/lcp_writepol
/usr/sbin/parse_err
/usr/sbin/tb_polgen
/usr/sbin/tpmnv_defindex
/usr/sbin/tpmnv_getcap
/usr/sbin/tpmnv_lock
/usr/sbin/tpmnv_relindex
/usr/sbin/txt-stat
/usr/share/doc/tboot
/usr/share/doc/tboot/COPYING
/usr/share/doc/tboot/Linux_LCP_Tools_User_Manual.pdf
/usr/share/doc/tboot/Makefile
/usr/share/doc/tboot/README
/usr/share/doc/tboot/man
/usr/share/doc/tboot/man/acminfo.8
/usr/share/doc/tboot/man/lcp_crtpconf.8
/usr/share/doc/tboot/man/lcp_crtpol.8
/usr/share/doc/tboot/man/lcp_crtpol2.8
/usr/share/doc/tboot/man/lcp_crtpolelt.8
/usr/share/doc/tboot/man/lcp_crtpollist.8
/usr/share/doc/tboot/man/lcp_mlehash.8
/usr/share/doc/tboot/man/lcp_readpol.8
/usr/share/doc/tboot/man/lcp_writepol.8
/usr/share/doc/tboot/man/tb_polgen.8
/usr/share/doc/tboot/man/txt-stat.8
/usr/share/doc/tboot/policy_v1.txt
/usr/share/doc/tboot/policy_v2.txt
/usr/share/doc/tboot/txt-info.txt
/usr/share/doc/tboot/vlp.txt
/usr/share/man/man8/acminfo.8.gz
/usr/share/man/man8/lcp_crtpconf.8.gz
/usr/share/man/man8/lcp_crtpol.8.gz
/usr/share/man/man8/lcp_crtpol2.8.gz
/usr/share/man/man8/lcp_crtpolelt.8.gz
/usr/share/man/man8/lcp_crtpollist.8.gz
/usr/share/man/man8/lcp_mlehash.8.gz
/usr/share/man/man8/lcp_readpol.8.gz
/usr/share/man/man8/lcp_writepol.8.gz
/usr/share/man/man8/tb_polgen.8.gz
/usr/share/man/man8/txt-stat.8.gz

References

Summary

In this tutorial we learn how to install tboot on Fedora 34 using yum and dnf.