NitroPC Pro 2 avec GPU externe¶
Note
Ce guide ne fonctionne que si vous utilisez l’image GPU Qubes OS OEM de Nitrokey que vous pouvez construire ``_.
Ce guide explique comment utiliser votre NitroPC avec une carte graphique externe (GPU) avec Qubes OS.
Avertissement
Suivre ce guide peut créer des problèmes de sécurité au sein de Qubes OS. Suivez-le à vos propres risques.
Créer un Qube Windows¶
Note
This will install a Windows Qube from the official trial ISO. If you want a full Windows experience then you will need to add a license key.
Cette partie utilise le projet ElliotKillick.
Ouvrez un terminal dans dom0 et assurez-vous que vous êtes connecté à Internet.
Installez les Qubes Windows Tools, dans dom0 :
sudo qubes-dom0-update qubes-windows-tools-4.1.69quand on vous le demande, appuyez suryet entrez.Note
Veuillez consulter les implications en matière de sécurité de l’installation de QWT.
Rendre le script d’installation exécutable, dans dom0 :
sudo chmod +x /install.shLancer le script d’installation, dans dom0 :
/install.shSi vous voyez ce message :
[+] Installation complete!vous pouvez continuer.At this point the script created a new Qube called windows-mgmt now we will download the ISO to create the Windows Qube.
Pour ce faire, nous devons copier le script
~/qvm-create-windows-qube/windows/isos/mido.shdu Qube windows-mgmt dans un Qube jetable avec une connectivité internet.Créez un nouveau Qube DVM (jetable) et donnez-lui au moins 10 Go d’espace de stockage privé.
Démarrez le Qube windows-mgmt et copiez le script, dans le Qube windows-mgmt :
qvm-copy qvm-create-windows-qube/windows/isos/mido.shpuis sélectionnez le DVM Qube (dispXXXX).Once the script is copied launch it, in dispXXXX :
./QubesIncoming/windows-mgmt/mido.sh win10x64Note
Dans ce guide nous installons Windows 10 mais d’autres versions de Windows sont disponibles vous pouvez les lister en utilisant
./QubesIncoming/windows-mgmt/mido.shIf you get a success message then you will need to copy the downloaded ISO from the DVM to the windows-mgmt Qube, in dispXXXX :
qvm-copy QubesIncoming/windows-mgmt/win10x64.isoand choose the windows-mgmt Qube.Une fois la copie effectuée, vous pouvez fermer votre DVM Qube.
Dans le Qube windows-mgmt :
mv QubesIncoming/dispXXXX/win10x64.iso qvm-create-windows-qube/windows/isos/(remplacez “dispXXXX” par le nom du Qube jetable que vous avez créé).Alors dans dom0 :
qvm-create-windows-qube -n sys-firewall -oy -i win10x64.iso -a win10x64-pro.xml work-win10Note
Vous pouvez pré-installer n’importe quel paquet à partir de ce site. Par exemple :
qvm-create-windows-qube -n sys-firewall -oyp firefox,notepadplusplus,office365proplus -i win10x64.iso -a win10x64-pro.xml work-win10Si le script s’arrête ou s’il est bloqué, réessayez jusqu’à ce que vous voyiez ce message :
[+] Completed successfully!Maintenant vous devez attacher votre GPU au Windows Qube, pour cela allez dans le Qube Manager et les options du Windows 10 Qube (assurez-vous que le Qube est éteint), sous l’onglet Devices sélectionnez votre carte graphique et passez-la à droite puis cliquez sur
Configure strict reset for PCI devicespuis sélectionnez votre carte et cliquez surOK.Maintenant que votre carte graphique est connectée à votre Windows Qube, vous devez installer les pilotes de votre carte. Recherchez
Check for updatesdans la barre de recherche puis cliquez surCheck for updates(vous devrez redémarrer plusieurs fois).
Now Windows will install all the drivers you will need to use your external graphic card. If you’re experiencing some problems make sure that you have enough space in your Windows Qube while installing updates.
Une fois cette opération terminée, vous pouvez connecter un écran secondaire à la carte graphique.
Si vous souhaitez utiliser une souris ou un clavier dédié pour le Windows Qube, vous devez utiliser sys-usb et y connecter le périphérique souhaité.
Créer un Qube Linux¶
Debian¶
Allez dans le gestionnaire de Qube et créez un nouveau Qube autonome, puis lancez les paramètres après la création.
In the « Advanced » tab change the mode to HVM and disable memory balancing and choose the amount of RAM you want.
In the devices tab select the GPU and pass it to the right then click on the
Configure strict reset for PCI devicesthen select your card and clickOK.Fermez les paramètres et démarrez le Qube.
Ajoutez non-free à votre liste de sources :
sudo sed -i '1 s/.*/& non-free/' /etc/apt/sources.listsudo apt updatesudo apt install nvidia-driver dbus-x11Now you will need to create 3 different files:
screen.conf: :
Section "Device" Identifier "GPU" # name of the driver to use. Can be "amdgpu", "nvidia", or something else Driver "nvidia" # The BusID value will change after each qube reboot. BusID "PCI:0:8:0" EndSection Section "Screen" Identifier "GPU screen" Device "GPU" EndSection
xorgX1.sh: :
#!/bin/bash binary=${1:?binary required} # Find the correct BusID of the AMD GPU, then set it in the Xorg configuration file pci=$(lspci | grep "VGA" | grep -E "NVIDIA|AMD/ATI" | cut -d " " -f 1 | cut -d ":" -f 2 | cut -d "." -f 1 | cut -d "0" -f 2) sed -i 's/"PCI:[^"]*"/"PCI:0:'$pci':0"/g' /home/user/screen.conf # Start the Xorg server for the X screen number 1. # The X screen n°0 is already used for QubesOS integration sudo startx "$binary" -- :1 -config /home/user/screen.confxfce.sh: :
#!/bin/bash sleep 5 && sudo setxkbmap -display :1 fr & /bin/sudo -u user PULSE_SERVER=unix:/run/user/1000/pulse/native bash -c 'sudo xhost + local:;/usr/bin/startxfce4'
sudo chmod +x xorgX1.sh xfce.shsudo ./xorgX1.sh ./xfce.sh
L’écran secondaire doit maintenant s’allumer et afficher un bureau Debian XFCE.
Si vous souhaitez utiliser une souris ou un clavier dédié pour le Linux Qube, vous devez utiliser sys-usb et y attacher le périphérique souhaité.