Improving security of the FreeBSD boot process TPM and Secure Boot in FreeBSD by Michal Stanek @BsdcanOrg
Improving security of the FreeBSD boot process TPM and Secure Boot in FreeBSD by Michal Stanek  @BsdcanOrg
Uploaded June 2019 | Updated September 2026, 1 hour ago
The talk describes recent security additions in the FreeBSD boot process.

TPM 2.0 devices are now supported in FreeBSD. They are most often referred to in the context of measured boot, i.e. secure measurements and attestation of all images in the boot chain. The TPM 2.0 specification defines versatile HSM devices which can also strengthen security of various other parts of your system. We will describe the basic features of TPM and mention some caveats and shortcomings which may have contributed to its limited adoption.

The presentation will include practical TPM use cases such as hardening Strongswan IPSec tunnels by signing with the TPM and locking in secrets to a particular boot hash chain.

The second part of the talk will describe UEFI Secure Boot support in the FreeBSD loader and kernel. The loader is now able to parse UEFI databases of keys and certificates which are used to verify a signed FreeBSD kernel binary, using BearSSL as the cryptographic backend.

The talk describes recent security additions in the FreeBSD boot process.

TPM 2.0 devices are now supported in FreeBSD. They are most often referred to in the context of measured boot, i.e. secure measurements and attestation of all images in the boot chain. The TPM 2.0 specification defines versatile HSM devices which can also strengthen security of various other parts of your system. We will describe the basic features of TPM and mention some caveats and shortcomings which may have contributed to its limited adoption.

The presentation will include practical TPM use cases such as hardening Strongswan IPSec tunnels by performing IKE-related cryptographic operations within the TPM, using private keys which never leave the device. Another example will be sealing secrets in TPM NVRAM with specific boot measurements (hashes) stored in PCR registers so that the secrets are locked in to a specific boot chain.

The second part of the talk will describe UEFI Secure Boot support in the FreeBSD loader and kernel. The loader is now able to parse UEFI databases of keys and certificates which are used to verify a signed FreeBSD kernel binary, using BearSSL as the cryptographic backend.
More Info:
bsdcan.org/2019/schedule/events/1070.en.html
Improving security of the FreeBSD boot process TPM and Secure Boot in FreeBSD by Michal StanekAlamosa: A Tiered Disk Block Cache for NetBSD By: Kira AshMigrating to FreeBSD from a Linux sysadmins perspective: Albert DenggNetwork Management with the OpenBSD Packet Filter ToolsetMassimiliano Stucchi, Peter N  M  Hansteen,BSDCan Saturday 2026-06-20: 1160Kirk McKusick: The Evolution of FreeBSD Governance   BSDCan 2018FreeBSD from a Linux developers perspective Its not all bad! D Scott PhillipsBSDCan Friday 2025-06-13: 1160Own The Stack FreeBSD from a Vendors Perspective Antranig VartanianBSDCan Friday 2026-06-19: 1160BGP Tutorial Massimiliano Stucchi, Tom SmythHeart ticking for a guest running on FreeBSD ARM hypervisor by Mihai Carabas
BSDCan |

Improving security of the FreeBSD boot process TPM and Secure Boot in FreeBSD by Michal Stanek

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER