NitroPC Pro 2 con GPU esterna¶
Nota
Questa guida funziona solo se si usa l’immagine della GPU OEM di Qubes OS di Nitrokey che si può costruire qui.
Questa guida spiega come utilizzare il NitroPC con una scheda grafica esterna (GPU) con Qubes OS.
Avvertimento
Seguire questa guida può creare alcuni problemi di sicurezza all’interno di Qubes OS. Seguitela a vostro rischio e pericolo.
Creare un Qube di Windows¶
Nota
This will install a Windows Qube from the official trial ISO. If you want a full Windows experience then you will need to add a license key.
Questa parte utilizza il progetto ElliotKillick.
Aprite un terminale in dom0 e assicuratevi di essere connessi a Internet.
Installare gli strumenti di Qubes per Windows, in dom0 :
sudo qubes-dom0-update qubes-windows-tools-4.1.69quando viene richiesto premereye dare invio.Nota
Consultare le implicazioni per la sicurezza dell’installazione di QWT.
Rendere eseguibile lo script di installazione, in dom0 :
sudo chmod +x /install.shAvviare lo script di installazione, in dom0 :
/install.shSe viene visualizzato questo messaggio:
[+] Installation complete!allora si può continuare.At this point the script created a new Qube called windows-mgmt now we will download the ISO to create the Windows Qube.
Per fare ciò è necessario copiare lo script
~/qvm-create-windows-qube/windows/isos/mido.shdal Qube windows-mgmt all’interno di un Qube usa e getta con connettività a Internet.Avviare un nuovo Qube DVM (usa e getta) e dotarlo di almeno 10 GB di memoria privata.
Avviare il Qube windows-mgmt e copiare lo script, nel Qube windows-mgmt:
qvm-copy qvm-create-windows-qube/windows/isos/mido.shquindi selezionare il Qube DVM (dispXXXX).Once the script is copied launch it, in dispXXXX :
./QubesIncoming/windows-mgmt/mido.sh win10x64Nota
In questa guida installiamo Windows 10, ma sono disponibili altre versioni di Windows che possono essere elencate utilizzando
./QubesIncoming/windows-mgmt/mido.sh.If you get a success message then you will need to copy the downloaded ISO from the DVM to the windows-mgmt Qube, in dispXXXX :
qvm-copy QubesIncoming/windows-mgmt/win10x64.isoand choose the windows-mgmt Qube.Una volta copiato, è possibile chiudere il DVM Qube.
Nel Qube windows-mgmt :
mv QubesIncoming/dispXXXX/win10x64.iso qvm-create-windows-qube/windows/isos/(sostituire “dispXXXX” con il nome del Qube monouso creato).Allora in dom0 :
qvm-create-windows-qube -n sys-firewall -oy -i win10x64.iso -a win10x64-pro.xml work-win10Nota
È possibile preinstallare qualsiasi pacchetto da questo sito. Ad esempio:
qvm-create-windows-qube -n sys-firewall -oyp firefox,notepadplusplus,office365proplus -i win10x64.iso -a win10x64-pro.xml work-win10Se lo script si interrompe o si blocca, riprovare finché non viene visualizzato questo messaggio:
[+] Completed successfully!Ora è necessario collegare la GPU a Windows Qube; per farlo, accedere a Qube Manager e alle opzioni di Windows 10 Qube (assicurarsi che Qube sia spento), nella scheda Dispositivi selezionare la scheda grafica e farla passare a destra, quindi fare clic su
Configure strict reset for PCI devices, quindi selezionare la scheda e fare clic suOK.Ora che la scheda grafica è collegata a Windows Qube, è necessario installare i driver della scheda. Cercare
Check for updatesnella barra di ricerca, quindi fare clic suCheck for updates(sarà necessario riavviare più volte).
Now Windows will install all the drivers you will need to use your external graphic card. If you’re experiencing some problems make sure that you have enough space in your Windows Qube while installing updates.
Una volta terminato, è possibile collegare uno schermo secondario alla scheda grafica.
Se si desidera utilizzare un mouse o una tastiera dedicati per Windows Qube, è necessario utilizzare sys-usb e collegare il dispositivo desiderato.
Creare un Qube Linux¶
Debian¶
Accedere a Qube manager e creare un nuovo Qube standalone e lanciare le impostazioni dopo la creazione.
In the «Advanced» tab change the mode to HVM and disable memory balancing and choose the amount of RAM you want.
In the devices tab select the GPU and pass it to the right then click on the
Configure strict reset for PCI devicesthen select your card and clickOK.Chiudere le impostazioni e avviare il Qube.
Aggiungete non-free al vostro elenco di sorgenti:
sudo sed -i '1 s/.*/& non-free/' /etc/apt/sources.listsudo apt update
sudo apt install nvidia-driver dbus-x11
Now you will need to create 3 different files:
screen.conf:
Section "Device" Identifier "GPU" # name of the driver to use. Can be "amdgpu", "nvidia", or something else Driver "nvidia" # The BusID value will change after each qube reboot. BusID "PCI:0:8:0" EndSection Section "Screen" Identifier "GPU screen" Device "GPU" EndSection
xorgX1.sh:
#!/bin/bash binary=${1:?binary required} # Find the correct BusID of the AMD GPU, then set it in the Xorg configuration file pci=$(lspci | grep "VGA" | grep -E "NVIDIA|AMD/ATI" | cut -d " " -f 1 | cut -d ":" -f 2 | cut -d "." -f 1 | cut -d "0" -f 2) sed -i 's/"PCI:[^"]*"/"PCI:0:'$pci':0"/g' /home/user/screen.conf # Start the Xorg server for the X screen number 1. # The X screen n°0 is already used for QubesOS integration sudo startx "$binary" -- :1 -config /home/user/screen.confxfce.sh:
#!/bin/bash sleep 5 && sudo setxkbmap -display :1 fr & /bin/sudo -u user PULSE_SERVER=unix:/run/user/1000/pulse/native bash -c 'sudo xhost + local:;/usr/bin/startxfce4'
sudo chmod +x xorgX1.sh xfce.sh
sudo ./xorgX1.sh ./xfce.sh
Ora lo schermo secondario dovrebbe accendersi e mostrare un desktop Debian XFCE.
Se si desidera utilizzare un mouse o una tastiera dedicati per Linux Qube, è necessario utilizzare sys-usb e collegare il dispositivo desiderato.