Is pureboot just heads? Is heads just a custom implementation of bootguard?

no, the Librem 14 uses a TPM 1.2 (it can be firmware-flashed to TPM 2.0 should we wish)

I’ve not looked at the state of things recently to be able to estimate that. If TPM2 support were implemented, me adding support for a new board would probably take an hour or less to get up and running, but I’m a veteran coreboot/Heads developer so not a great metric to use.

only the LK/NK are supported currently. I’m not sure what other keys are capable (if any) and support would likely needed to be explicitly added

1 Like