In this post we trace files in Yocto images back to their packages and recipes, and dig into why they’re actually installed.
Continue reading...yocto
Open-Source Contribution: Yocto
It’s been a while since the last post here. And it’s been even a longer while since I’ve made an open-source contribution. However, during this summer...
Continue reading...Yocto Hardening: File System Integrity with dm-verity
In this part of the Yocto hardening we talk about how to verify the integrity of a file system with dm-verity in embedded systems.
Continue reading...Yocto Hardening: Read-Only Rootfs
Let’s continue the always-so-fun task of hardening the Yocto systems. This time, we will consider the file system integrity.
Continue reading...Building Sulka: Six Months of Embedded Linux Development
Half a year ago, I started a little hobby project of building a hardened Yocto distro, Sulka. I thought that I’d share what’s happened over the past months.
Continue reading...Yocto Hardening: Kernel Module Signing
This time we have a relatively simple and effective hardening measure that may prevent big headaches: kernel module signing.
Continue reading...Yocto Hardening: Multi-Factor Authentication
In this blog post, I’ll show how to integrate Google Authenticator into a Yocto system to enhance the security of remote login flows.
Continue reading...Introducing Sulka, the Hardened Yocto Distro
For years I have been telling myself that it’s a bit too much for a single person to try and manage a distro, but now I think it’s time to give it a go.
Continue reading...Configuration with PACKAGECONFIG in Yocto
The OpenEmbedded build system used by the Yocto Project has a powerful feature that is slightly hidden in the documentation: package configuration.
Continue reading...Encrypting In Yocto With fscryptctl
In this blog text I’ll briefly cover how to use fscryptctl to encrypt and decrypt directories in an embedded Linux system.
Continue reading...








