Download · esOS 1.0

Download esOS

One hybrid image boots on UEFI and legacy BIOS computers, from a USB stick or a DVD. Check the download before you write it to a stick.

Release files

esOS 1.0 for 64-bit x86 computers (x86-64-v3).

FileSizeSHA-256
esos-1.0-x86_64.iso
Bootable image (UEFI + BIOS, USB or DVD)
26 MBd3917ed1db13ea500fb7069bfee80888f8b9c1ed8d4d502b241a8f274b610ee9
esos-1.0-source.tar
Complete source code
406 MBc626a101c34ce6e38258f7fbc0f383220f5178d8ac55bf32800fe95cfb59a214
RELEASE-NOTES.txt
Release notes
3.5 KB8a3110b03d824832ad74af66d9859fc0ce9925b364ae51af7daec0deb3339192
THIRD-PARTY-NOTICES.txt
Third-party components and licenses
8.3 KB4492a732d417273d1a7376c4f6116f1adef254d02795da97c1559b1515ac7121
SHA256SUMS
Checksums of the files above
346 bytes–
SHA256SUMS.asc
OpenPGP signature of SHA256SUMS
228 bytes–

Before you start

System requirements

esOS is compiled for the x86-64-v3 feature level. On an older processor it does not start, and it may stop without an error message.

Processorx86-64-v3 (AVX2, BMI2, FMA, MOVBE): Intel Haswell (2013) or newer, AMD Excavator or Zen and newer
Memory1 GB minimum, 2 GB recommended
FirmwareUEFI with Secure Boot off, or legacy BIOS
Boot mediaUSB stick of 64 MB or more, or a DVD
Networknot used

From download to first boot

Verify, write, boot

  1. Verify the download

    Download SHA256SUMS into the same folder as the image and check it. The line for the image must end in OK.

    $ sha256sum -c SHA256SUMS --ignore-missing

    On macOS: shasum -a 256 -c SHA256SUMS --ignore-missing. On Windows PowerShell: Get-FileHash esos-1.0-x86_64.iso and compare with the value in the table above.

    Then check that the checksum file was signed by the esOS release key:

    $ gpg --import esos-release-key.asc
    $ gpg --verify SHA256SUMS.asc SHA256SUMS

    Release key fingerprint: CEBA 85D7 8B1B 06F4 BA1C 06B3 826A 3D20 1AA1 34B5

  2. Write the image to a USB stick

    Everything on the stick is erased. Make sure you select the stick and not another disk.

    Linux

    Find the stick with lsblk (for example /dev/sdb), then:

    $ sudo dd if=esos-1.0-x86_64.iso of=/dev/sdX bs=4M status=progress conv=fsync

    macOS

    Find the stick with diskutil list (for example /dev/disk4), unmount it, then write to the raw device:

    $ diskutil unmountDisk /dev/diskN
    $ sudo dd if=esos-1.0-x86_64.iso of=/dev/rdiskN bs=4m

    Windows

    Use Rufus and choose DD Image mode when it asks how to write the image, or use balenaEtcher.

  3. Boot from the stick

    Open the computer's boot menu while it starts. The key depends on the manufacturer; it is usually F12, F11, F10 or Esc. On an Intel Mac, hold Option (⌥) and choose the USB stick; it is labelled esOS 1.0 or EFI Boot.

    The esOS menu offers the normal start, a verbose boot log, a serial console, and a safe mode with the IOMMU and kernel mode setting turned off. After boot, see first steps.

    Secure Boot

    The esOS 1.0 image is not signed for Secure Boot. Turn Secure Boot off in the firmware settings, or the computer will refuse to start it.

Release notes

What is in esOS 1.0

The first public release. The full notes are in RELEASE-NOTES.txt.

  • Encryption Studio X (esx): password and RSA file encryption, RSA key generation from 2048 to 16384 bits.
  • LUKS2 encrypted containers with cryptsetup 2.8.8.
  • OpenSSL 3.5.8, a long-term support release.
  • Reads and writes ext4, FAT, exFAT, NTFS, ISO 9660, Btrfs and XFS on USB, NVMe, SATA and SD/eMMC storage.
  • keyboard_setup with nine layouts, chosen from a menu or detected from a few key presses.
  • The console repairs itself at the next prompt after a binary file was printed to it.

Known limitations

  • No network, by design. Exchange files with USB storage.
  • Nothing is saved between boots, including the keyboard layout.
  • Some punctuation keys sit elsewhere on Apple keyboards; if detection picks the wrong layout, choose it from the menu.