NitroPC Pro 2 com GPU externa¶
Nota
Este guia só está a funcionar se usar a imagem de GPU Qubes OS OEM da Nitrokey que pode ser construída aqui.
Este guia explica como utilizar o NitroPC com uma placa gráfica externa (GPU) com o Qubes OS.
Aviso
Seguir este guia pode criar alguns problemas de segurança no Qubes OS. Siga-o por sua própria conta e risco.
Criar um Qube Windows¶
Nota
This will install a Windows Qube from the official trial ISO. If you want a full Windows experience then you will need to add a license key.
Esta parte está a utilizar o projeto ElliotKillick.
Abra um terminal no dom0 e certifique-se de que tem a Internet ligada.
Instalar as ferramentas Qubes para Windows, no dom0:
sudo qubes-dom0-update qubes-windows-tools-4.1.69quando solicitado, primaye introduza.Nota
Consulte as implicações de segurança da instalação do QWT.
Make the install script executable, in dom0 :
sudo chmod +x /install.shLançar o script de instalação, em dom0 :
/install.shSe vir esta mensagem:
[+] Installation complete!, pode continuar.At this point the script created a new Qube called windows-mgmt now we will download the ISO to create the Windows Qube.
Para o fazer, precisamos de copiar o script
~/qvm-create-windows-qube/windows/isos/mido.shdo Qube windows-mgmt para um Qube descartável com ligação à Internet.Inicie um novo Qubes DVM (descartável) e dê-lhe pelo menos 10 GB de armazenamento privado.
Inicie o Qube do windows-mgmt e copie o script, no Qube do windows-mgmt:
qvm-copy qvm-create-windows-qube/windows/isos/mido.shdepois selecione o Qube DVM (dispXXXX).Once the script is copied launch it, in dispXXXX :
./QubesIncoming/windows-mgmt/mido.sh win10x64Nota
Neste guia, instalamos o Windows 10, mas outras versões do Windows estão disponíveis, você pode listá-las usando
./QubesIncoming/windows-mgmt/mido.shIf you get a success message then you will need to copy the downloaded ISO from the DVM to the windows-mgmt Qube, in dispXXXX :
qvm-copy QubesIncoming/windows-mgmt/win10x64.isoand choose the windows-mgmt Qube.NitroPad NS50:
No Qube do windows-mgmt:
mv QubesIncoming/dispXXXX/win10x64.iso qvm-create-windows-qube/windows/isos/(substitua “dispXXXX” pelo nome do Qube descartável que criou).Então, em dom0 :
qvm-create-windows-qube -n sys-firewall -oy -i win10x64.iso -a win10x64-pro.xml work-win10Nota
Pode pré-instalar qualquer pacote a partir de deste sítio. Por exemplo:
qvm-create-windows-qube -n sys-firewall -oyp firefox,notepadplusplus,office365proplus -i win10x64.iso -a win10x64-pro.xml work-win10Se o script parar ou se ficar preso, tente novamente até ver esta mensagem:
[+] Completed successfully!Para o fazer, aceda ao Qube Manager e às opções do Windows 10 Qube (certifique-se de que o Qube está desligado), no separador Devices (Dispositivos) selecione a sua placa gráfica e passe-a para a direita, depois clique em
Configure strict reset for PCI devices, depois selecione a sua placa e clique emOKAgora que a placa gráfica está ligada ao Windows Qubes, é necessário instalar os controladores da placa. Procure por
Check for updatesna barra de pesquisa e, em seguida, clique emCheck for updates(será necessário reiniciar várias vezes).
Now Windows will install all the drivers you will need to use your external graphic card. If you’re experiencing some problems make sure that you have enough space in your Windows Qube while installing updates.
Quando terminar, pode ligar um ecrã secundário à placa gráfica.
Se pretender utilizar um rato ou teclado dedicado para o Windows Qubes, terá de utilizar o sys-usb e ligar-lhe o dispositivo pretendido.
Criar um Qube Linux¶
Debian¶
Ir para o gestor do Qube e criar um novo Qube autónomo e iniciar as definições após a criação.
In the «Advanced» tab change the mode to HVM and disable memory balancing and choose the amount of RAM you want.
In the devices tab select the GPU and pass it to the right then click on the
Configure strict reset for PCI devicesthen select your card and clickOK.Fechar as definições e iniciar o Qubes.
Adicione o non-free à sua lista de fontes:
sudo sed -i '1 s/.*/& non-free/' /etc/apt/sources.listsudo apt updatesudo apt install nvidia-driver dbus-x11Now you will need to create 3 different files:
screen.conf:
Section "Device" Identifier "GPU" # name of the driver to use. Can be "amdgpu", "nvidia", or something else Driver "nvidia" # The BusID value will change after each qube reboot. BusID "PCI:0:8:0" EndSection Section "Screen" Identifier "GPU screen" Device "GPU" EndSection
xorgX1.sh:
#!/bin/bash binary=${1:?binary required} # Find the correct BusID of the AMD GPU, then set it in the Xorg configuration file pci=$(lspci | grep "VGA" | grep -E "NVIDIA|AMD/ATI" | cut -d " " -f 1 | cut -d ":" -f 2 | cut -d "." -f 1 | cut -d "0" -f 2) sed -i 's/"PCI:[^"]*"/"PCI:0:'$pci':0"/g' /home/user/screen.conf # Start the Xorg server for the X screen number 1. # The X screen n°0 is already used for QubesOS integration sudo startx "$binary" -- :1 -config /home/user/screen.confxfce.sh:
#!/bin/bash sleep 5 && sudo setxkbmap -display :1 fr & /bin/sudo -u user PULSE_SERVER=unix:/run/user/1000/pulse/native bash -c 'sudo xhost + local:;/usr/bin/startxfce4'
sudo chmod +x xorgX1.sh xfce.shsudo ./xorgX1.sh ./xfce.sh
Agora o ecrã secundário deve ligar-se e mostrar um ambiente de trabalho Debian XFCE.
Se quiser usar um rato ou teclado dedicado para o Linux Qubes, então precisa de usar o sys-usb e ligar o dispositivo desejado a ele.