Eloi is a technical steering commitee chair of LF Energy SEAPATH.

Eloi is born in Brest and began his career in Paris where he worked for 3 years at NDS (then Cisco), world leader in software solutions for video set-top boxes based on Linux. In October 2012, Eloi joined the Industrial Solutions department at Savoir-faire Linux (Montreal, Quebec). He developed his embedded Linux expertise in different areas such as multimédia, avionic systems and a secure and distributed audio & video communication platform: GNU Jami. His last mission in Canada was to lead the project to contribute to FFmpeg for the new SMPTE ST 2110 standard, leading to presentations in 2017 at the SMPTE Montreal group as well as at the IBC conference in Amsterdam on the European Broadcasting Union (EBU) booth.

Eloi went back to France in the summer of 2017, as technical leader and project director of Savoir-faire Linux France. Eloi works on various industrial projects using Yocto in the energy, transport, medical and robotics sectors. Since September 2020, Eloi is also Director of Operations at Savoir-faire Linux, and lead a team of 15 engineers.

Eloi initated the development of LFEnergy Seapath in February 2020. Eloi is chair of LF Energy SEAPATH Technical Steering Committee (TSC) and SEAPATH Technical Advisory Council (TAC) representative. Savoir-faire Linux joined LFEnergy in 2020. Eloi presented various conferences on Seapath: – Open Source Experience 2021 : https://youtu.be/oxzzOBbCysw – LFEnergy summit 2021: https://www.youtube.com/watch?v=qm_nQef5_BM – LFEnergy Embededded Summit 2023: https://sched.co/1LaQn

Accepted Talks:

Hardening Debian from UEFI to Userland, an example with LF Energy SEAPATH

Mathieu and Eloi are the main contributors of LF Energy SEAPATH which use Debian as an VM hypervisor to host critical applications within Digital Substations.

SEAPATH is used in production by RTE, the french electricity Transmission Service Operator (TSO). Because SEAPATH is used in a critical environment, cybersecurity hardening need to be deployed on top of Debian.

This talk walks through the full system hardening process on Debian, starting with UEFI secure boot configuration and ending at service-level protections. We’ll cover secure bootloader (GRUB) configurations, encrypted and integrity-verified storage (dm-crypt, dm-verity), kernel hardening via command-line parameters, systemd service sandboxing, and general Debian-level hardening strategies.

Attendees will gain actionable steps to improve the security posture of their Debian deployments, whether on laptops, servers, or embedded systems.