"Attests the software version is the version that is valid and shipped by the Oxide Computer Company" So in other words these servers will implement restrictive code signing practices and will be vendor-controlled, not owner-controlled? This is not my idea of "secure", and really in the wake of things like the Solarwinds or RSA hacks it shouldn't be anyone's idea of secure. Vendor-holds-the-keys is not an acceptable…
Secure boot chain
Our boot flow is secure by default. Our firmware is open source and attestable.
There is a link to "Explore Repos." Is coreboot the open source firmware?
https://github.com/oxidecomputer/coreboot
Open Firmware is different than coreboot.