Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #65071
| From | Marek Rusinowski <marekrusinowski@gmail.com> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#939773: linux-image-5.2.0-2-amd64: MOK key not used for verification of modules signatures. |
| Date | 2019-09-08 19:50 +0200 |
| Message-ID | <yE9u1-7AB-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
Package: src:linux Version: 5.2.9-2 Severity: important Dear Maintainer, I've updated kernel from 4.19 to 5.2 and kernel stopped accepting modules signed with MOK key. I have secure boot enabled on my system and enrolled generated MOK key. I use some out-of-tree modules that use DKMS. In the previous version of the kernel I was signing those modules with the MOK key and they loaded just fine as MOK key was loaded into the trusted keyring in the kernel. After the kernel update, MOK key gets inserted into the .platform keyring (I see CONFIG_INTEGRITY_PLATFORM_KEYRING is set to true in the kernel config) which apparently isn't used for validation of module signatures so I'm unable to load MOK signed modules. I would expect this to still work as the only option I have right now for using DKMS modules is building and using my own kernel image... This is also the method described in https://wiki.debian.org/SecureBoot. I've found this related bug in Fedora: https://bugzilla.redhat.com/show_bug.cgi?id=1701096. There are some links to upstream patches but I've just checked linux master and kernel/module_signing.c is still using only secondary_trusted_keyring and builtin_trusted_keyring to verify modules signatures. Thank you, Marek Rusinowski
Back to linux.debian.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#939773: linux-image-5.2.0-2-amd64: MOK key not used for verification of modules signatures. Marek Rusinowski <marekrusinowski@gmail.com> - 2019-09-08 19:50 +0200 Bug#939773: Duplicate Marek Rusinowski <marekrusinowski@gmail.com> - 2019-09-14 17:20 +0200 Bug#939773: marked as done (linux-image-5.2.0-2-amd64: MOK key not used for verification of modules signatures.) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2019-10-21 00:10 +0200 Bug#939773: marked as done (linux-image-5.2.0-2-amd64: MOK key not used for verification of modules signatures.) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2019-11-09 22:20 +0100
csiph-web