
Armed to Boot: an enhancement to Arm's Secure Boot chain
1/25/2023
This post details the implementation of Single Domain Secure Boot (SDSB) for Cloudflare's Arm server fleet, specifically using Ampere Altra Max CPUs. It explains the limitations of the standard Arm Trusted Firmware (ATF) Secure Boot for server environments and how SDSB extends the trust anchor to the UEFI firmware by incorporating a hash of Cloudflare's public signing key into the SoC's eFuses. The process involves generating certificates, customizing firmware with ODMs, signing UEFI images, and provisioning eFuses during manufacturing.
