Installing Qubes 4 templates in Qubes 2?

Howdy Folks,

Trying to install some later templates onto earlier Qubes. Is it possible? Or do I need to downgrade any packages?
Keeps telling me that QREXEC doesn’t start, from the QM.

I’m trying to use Templates from 4 in 2 as 2 doesn’t need the VT-D to be able to use the virtualisation technology in the system.

Is there anything that I should be installing in Domain-0 Fedora to be able to get it to work?
Do I need to run update in the guest? If so, how do I get the update packages for the operating system but not Qubes Packages and have the Qubes packages still function properly?

I have to ask: why qubes 2? :smiley: VERY old airgap?

Qubes 2 doesn’t require VT-D to make things work. It can get the devices and separate them without it.

And it allows for attaching of physical drives as it doesn’t have the blockages that the recent versions do, which I still don’t understand why such a stupid thing was done.

Also, Qubes 2 runs in less RAM than Qubes 4.

Qubes 4 requires 4 times as much RAM to run properly.

Qubes 1 ran in almost no RAM.

Qubes 3.2 was probably the best so far as it had the best of everything. It had brillient security, ran Windows seamlessly (in all forms), and ran whatever unix distribution I wanted, or even OSX. I could also insert my HDs and just run off them instead of having to image them to the drive to run things, or do things in a such a stupid way to attach them then detach them to boot and all it isn’t funny…

So 3.2 was the best overall.

The only problem with the pre-4 versions, they require a different GPU when I’m doing the install. Because they just won’t work with the NVIDIA cards. I have to install a 20 year old GPU instead of a 15 year old GPU.

4+ has a lot of issues that have never been resolved since 4.0 RCs

4+ doesn’t allow for drive usage.

4+ doesn’t have an easy way to configure things in the setup like the others did.

So for this case, I need Q2 since the motherboard doesn’t have VT-D on it. The CPU does, and it should be working, but it doesn’t see it or find it or use it. So the old CPU that had no VT-D on it, still couldn’t install newer than version 2 and have the NIC added to a guest.

So this is just something that is there in 2 that isn’t there in 4, the better compatability.

Since the machine is an old AIO I can’t just upgrade the board like I normally would.

It’s just a small machine that I want to get things working on to be able to take somewhere to use to be able to perform certain tasks and maintain security.

I also want to install it on my old thinkpad as well and have the security on there. As that has the full portability and secure hardware.

So I hope that that explains my thoughts, reasonings and feelings on the differences.

I use 4.3 on my main PC, and still wish that I had the ability to use the drives like I could in 2, but I can’t, so I manage to work around things like that on this hardware as I have dedicated PCIE SATA card that I can hotswap the drives on that is set for the specific virtual and ignored by Qubes so it doesn’t attach the drives to it. It’s an expensive workaround, but it works… I have a 6 port card on my server that runs Qubes so that I have the NAS virtualised on there.

So I’m not sayign that any are unworkable and things don’t work for many peoples usages, as just the way that things are is fine for most people, I just have uses for the system that people don’t normally think about, and that people have removed from the operating system over time without a way to override it or use certain things the way that you used to be able to.

Which I have been querying about disabling certain features on a per guest basis in other threads as well.

The AIO just needs to have WhoNix gateway on it as well as basic systems that can perform accurately. So I can fix much of that as the inbuilt systems are mainly acting as networking. I have my own update server for it so I can update from installer to the final before removal from the Qubes Update servers at least.

I’ll post more shortly if you need more information. I have to get the little one in to bed and sleeping.

Well Qubes 2 also runs a XEN version that has no more security upgrades.

I suppose the qvm-* tools and alike in Qubes 4 templates are incompatible with Qubes 2, hence the best option, if you really choose to keep using Qubes 2, which you should not on a machine connected to the internet (or in general), is to try and find (are they still somewhere?) Qubes 2 templates.

Ok, let’s see who’s optimistic enough to try to explain why 4.3 is better than any earlier version of Qubes.

The one who succeeds, has a month of a free beer on me.

Because it is actively maintained and has security upgrades.

Thanks, but I don’t drink alcohol. I like red wine for cooking though :slight_smile: Like a nice steak sauce or something.

For me 4.3 is slightly better than 4.2 (new USB/PCI handling is awesome, preloaded DispVMs are cool) and 4.2 was slightly better than 4.1 (for example with better GPU PCI passthrough), so by principle of mathematical induction it is better than at least some previous versions.

Also, @kuhbs is quite right with the security angle.

And it allows for attaching of physical drives as it doesn’t have the blockages that the recent versions do, which I still don’t understand why such a stupid thing was done.

Could you elaborate on what that means?

For the security angle, doesn’t mean much when you have a secure system and good configuration and know what you are doing.

And I know what I’m doing with it, so there is no actual issue security wise.

Qubes is generally used just for networking side of things anyway.

As for attaching physical drives, it means exactly what I say.

The qubes files I just map to a physical device, and it works.

so root.img is mapped to /dev/sdc and private.img is mapped to /dev/sdd.

And I have an ISO that I boot to, and it allows me to do drive cloning and such.

Other than that I can have root mapped to sdb and private as an image so it boots to a separate drive and has data on the qubes storage drive.

These days, can’t attach anything or link anything in such a way as it tries to do verification on the image files and if it is a link it just doesn’t validate it so it doesn’t allow it.

You don’t know what you are doing. It is not a secure system, it is a very outdated system with known vulnerabilities that will never be patched because it is EOL. If you describe in details the problems you had on R4.3, the forum can help.

I have no idea what this means. There are no links, no explanation. If you want help, don’t assume you know what you are doing, this will clear your mind and allow receiving feedback and possibly help elaborate your issues better.

You are more secure installing another non hypervisor based OS that is up-to-date than a very EOL version of Qubes. How much more secure? I don’t know, I just know that EOL is vulnerable.

@ben-grande I think if it is not immediately obvious to a user how EOL impacts security, then explaining it will not produce the desired/expected result either.

So let him drive an outdated Qubes. If his security would truly depend on it, he most likely wouldn’t, or if it does, we can’t help him with it either.

1: Ben,

I do know what i’m doing with it, and I know what the vulnerabilities are. But for what I want to use it for it’s not important. It is as secure as it needs to be with the way it works. And I know how secure it is because being a Cyber Security Professional I have done testing and exploit attacks on Qubes 2 back when I was at TAFE, and not me nor even 99% of the other people at the institute could break into my system. the couple that did fell to the honeypot and got exploited themselves. So yes, I made it a secure system for what was there at that time.

I have described the issues and problems, please, re-read and tell me what it is that you don’t actually understand.

I have raised about the issues in the past from 4.0.

It doesn’t allow for drive usage, correct, if you don’t understand, read the previous post I made here that explains it in detail.

Previously the setup functionality was simple and straight forward, not focused on being wanky graphics. With configuration maybe the wanky graphics are just annoying me enough that I get too frustrated with it, but I can’t find half the options I need most of the time.

The board doesn’t handle VT-D, so I have to use Qubes 2. If there was the option on install to disable VT-D requirement and use a less secure system for version 4+ then I would install 4+, but in 4+ I can’t attach a network card to a guest to create a net-vm, but I can in 2.

Vulnerable or not, it’s the guest systems that need to be able to handle the protocols and have the protection.

Anyone that is building a system should have backwards compatability in there so that the new systems can be installed on the old domain-0, or at least the option to enable an older API set.

Just my opinion on things.

2: Kuhbs,

It doesn’t matter how EOL affects things, I just need what I need for the machine I need to put it on. It’s that simple. It isn’t doing anything dangerous on the internet, it just does general work and has things that don’t talk to each other directly. If I was doing what I do on my main PC then I wouldn’t use anything outdated like that. My main PC does a lot of stuff. This other PC is a machine for doing phone backups and using separation to have different “PCs” identified by the software so the phones don’t overwrite each other in the software.

So it really doesn’t matter if it’s outdated or not. As long as I secure the system, it’s all fine, because nothing can affect what can’t be affected in that way because of the separation and knowing what I’m doing. After all, I was rewriting the Qubes Manager to utilise 1/100th of the RAM requirement, and have more control over things.

3: Ben,

I know how VTD and VTX and the AMD variants work. I have been running virtualised systems since 2003. The issue is just the VTD, it has VTX.

The problems with it in 4+ and not being able to assign drives is also an issue I face on my main PC. Very frustrating to have limited functionality and capabilities when it comes to that feature set.

Having to create loop after loop to loop into loops and link loops to devices is just frustrating as I can’t simply automate it yet. I’m still working on getting it to just do it automatically and intercept the loop creation and redirect to the devices, but the Qubes Python code is just very messy and all over the place with no structure or semblance of thought. So it’s taking me a while. I can’t even find the other bits I’ve been trying to find as the “executable” code just calls “main()” and that’s all that is in the file… And that’s the problem with 95% of the qubes executables. So it takes me time to sort through it all.

@Vael_S Bit much textwall, so I didn’t read it.

Why dont you just upgrade, then its all supported again, and its secure as well. All the templates you need will just work on 4.3 / latest.

Go back and read it, your question is answered in there, and I’m not going to post all that again for you to not read it again.

Bro why don’t you just upgrade. It will fix all of your issues.

Qubes 2 is EOL.

Read the answer, the text is the answer, it tells you everything in detail.

Can you summarize it a bit its so much to read.

I don’t get why you don’t just upgrade. Qubes 2 is EOL.

Primary reason…

: Read original post.

Howdy

As you will be aware there are significant architectural differences
between current Qubes and Qubes2.
The short but full answer to your question is “No, it is not possible.”

It would be possible, of course, for you to recreate the templates in
Qubes2, by installing all relevant packages and configuring as you like.
You could get a list of installed packages from the template, and
install in to the new, copying across configurations. I suspect that
will be faster than trying to downgrade the Qubes packages, and relevant
requirements.

As you now have a full answer to your question I see no benefit in
prolonging the agony any further. Good luck with the downgrades.

I never presume to speak for the Qubes team. When I comment in the Forum I speak for myself.

Okay, so I can’t just upgrade the OS, I have to install the OS from scratch and install the Qubes Packages for 2.0 ? But doesn’t it need the early kernel? Or will the later kernels be fine?
Does it have to have MicroSoft SystemD on the guests though?