What is secure boot? webinar poster

What is secure boot?

Watch Now

Speakers:

  • Zane Hamilton, Vice President, CIQ

  • Neil Hanlon, Solutions Architecture, CIQ


Note: This transcript was created using speech recognition software. While it has been reviewed by human transcribers, it may contain errors.

Full Webinar Transcript:

Zane Hamilton:

Tell us a little about Secure Boot, but what is it, how is it beneficial, and what to watch out for? 

Neil Hanlon:

Absolutely. Secure Boot's part of UEFI is the next generation of BIOS Boot to the Legacy BIOS Boot. And it developed in response to malware rootkits that we're able to get in, replace that boot loader, that first stage boot loader in your environment. And it's essentially a cryptographic way of ensuring that the operating system you're trying to boot from is not a virus. That's done right now through a central authority through Microsoft, and they have a portal where we upload our certificate and have them cross sign it. It's valid for the certificate loaded into a piece of hardware soldered onto your motherboard if you have a new computer called the TPM or a trusted platform module. That trusted platform module enables secure storage of encrypted secrets like certificates and keys. This allows us to have a secure boot environment where Microsoft has validated that the boot loader Rocky has built is not a virus. It's also built in a secure, trusted environment that we maintain on the Rocky Enterprise Software Foundation.

Transcript

tell us a little bit about secure but what is it how is it beneficial and things to watch out for yeah sure absolutely so security is part of uefi which is the next generation of the bios boot the legacy bios boot and it was uh it developed in response to malware rootkits in particular that were able to get in replace that bootloader that first stage bootloader in your environment and it's essentially a cryptographic way of ensuring that the operating system that you're trying to boot from is not a virus and that's kind of done right now through a central authority through microsoft and they have

a portal where we go and upload our certificate and um have them cross sign it so it's it's valid for the certificate that's loaded into a piece of uh hardware that's soldered onto your motherboard if you have a new computer called the tpm or a trusted platform module and that trusted platform module enables secure storage of uh encrypted secrets like certificates and keys and so what this allows us to do is have the secure boot environment where microsoft has validated that the bootloader that rocky has built is not a virus essentially and um it's also built in a secure trusted environment that we maintain on

the rocky enterprise software foundation

Built for scale. Chosen by the world’s best.

2.75M+

Rocky Linux instances

Being used world wide

90%

Of fortune 100 companies

Use CIQ supported technologies

250k

Avg. monthly downloads

Rocky Linux

Have questions about your infrastructure?

Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.

Talk to an Expert