Secure Boot Sequence
-
Plug in the PureBoot Smart Card
-
Plug in AirgapOS Storage Device
-
Turn on the machine
-
Press space when the message "Automatic boot in 5 seconds unless interrupted by keypress..."
-
Once in the PureBoot Boot Menu, navigate to "Options -->" and press Enter
-
Navigate to "Exit to recovery shell" and press enter
-
Use the command
source /etc/gui_functions
to load gui functions -
Use the command
mount_usb
to mount the Storage Device which containsairgap.iso
and the detached GPG signature. -
Type
sha256sum /media/airgap.iso.asc
-
Verify the hash that appears using whatever number of witnesses the Quroum agreed are necessary for witnessing key parts of the Ceremony. Each witness should bring their own piece of paper with the hash written out based on the binary they built on their own system according to the AirgapOS Setup Playbook.
-
Once everyone is satisfied that the hash matches, the computer should be be restarted.
-
Press space when the message "Automatic boot in 5 seconds unless interrupted by keypress..."
-
Once in the PureBoot Boot Menu, navigate to "Options -->" and press Enter
-
Navigate to "Boot Options -->" and press enter
-
Navigate to "USB boot" and press enter
-
Ensure that
/media/airgap.iso
is selected and press Enter -
Once booted, verify the version of the software matches the AirgapOS Hash which was noted during the AirgapOS Setup.