Has anybody here experience with Gentoo as OS in dom0?
2 Likes
janglingquo_575:
as OS in dom0
You can’t change the OS in dom0 at the moment. See this:
opened 04:34PM - 18 Apr 16 UTC
C: core
P: major
We have discussed this numerous times but don't have an issue to track these dis… cussions. It would be worth understanding what would be needed to change dom0 from Fedora to Debian (say Debian 8). Benefits include:
- increased hardware compatibility
- incorporate serious work taken towards reproducible builds
- better firstboot installer
- better (slower) release cycle than Fedora with longer-term support
- other things?
This ticket does not encompass modifying the desktop environment.
See also:
no specifics
My impression from this and other threads is:
the core team works on moving more and more hardware handling into dedicated qubes (increased security through compartmentalization): sys-net, sys-usb, sys-audio, sys-gui, …?
the distribution used in system qubes is up to the user (to a certain degree, based on what is officially supported and what the skill level of the user is to go beyond that).
eventually dom0 will have little left to do, at which point dom0 might migrate…
1 Like
Is the Gui-VM still being developed?
1 Like
Sorry my English. Can you tell me which is the most recent development
in GUI-VM?
1 Like
Is Alpine Linux still the leading candidate for dom0 security wise?
What about Open/Hardened BSD?
Is secureblue a candidate?
2 Likes
AFAIK my links show the latest developments.
The answer is in this discussion, which I gave above:
opened 04:34PM - 18 Apr 16 UTC
C: core
P: major
We have discussed this numerous times but don't have an issue to track these dis… cussions. It would be worth understanding what would be needed to change dom0 from Fedora to Debian (say Debian 8). Benefits include:
- increased hardware compatibility
- incorporate serious work taken towards reproducible builds
- better firstboot installer
- better (slower) release cycle than Fedora with longer-term support
- other things?
This ticket does not encompass modifying the desktop environment.
Also this post, which I gave above, explains why the dom0 distribution shouldn’t matter:
1 Like
what do you think about hardened Fedora distros like secureblue
1 Like
It’s a great distro, and there’s a plan to have a Template with it in Qubes. However I’m not sure which threats you expect in dom0, where this distro would help. Could you name them?
Related earlier discussion:
Why bother using Fedora, when Silverblue can be used, ensuring atomic updates? It’d just make dom0 more reliable and less error-prone to updates being applied properly. Has this been attempted before?
Another one:
Alt RPM Distro (CentOS?) in dom0 - #24 by Insurgo .
1 Like
It isn’t only for dom0. You’re right that dom0 is unlikely to be compromised except
for a supply chain attack on Fedora.
I would say the biggest threat would be a supply chain attack on Fedora.
But mainly it would be for the VM security, because these VMs are network
facing.
1 Like