Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #59614 > unrolled thread

State of SecureBoot for Debian GNU/Linux?

Started byPhilipp Hahn <hahn@univention.de>
First post2017-12-11 18:20 +0100
Last post2017-12-12 01:50 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  State of SecureBoot for Debian GNU/Linux? Philipp Hahn <hahn@univention.de> - 2017-12-11 18:20 +0100
    Re: State of SecureBoot for Debian GNU/Linux? Ben Hutchings <ben@decadent.org.uk> - 2017-12-12 01:50 +0100

#59614 — State of SecureBoot for Debian GNU/Linux?

FromPhilipp Hahn <hahn@univention.de>
Date2017-12-11 18:20 +0100
SubjectState of SecureBoot for Debian GNU/Linux?
Message-ID<uVzUe-85t-7@gated-at.bofh.it>
Hello fellow DDs,

I'm employed by Univention and we ship our Debian based distribution
"Univention Corporate Server" with UEFI support. Currently we're
building our own Linux kernel and have our own signed version of shim
and grub.

For our next release, which will be based von Debian-Stretch, we're
considering to switch to the Debian provided kernel.

If read <https://wiki.debian.org/SecureBoot> and
<https://bugs.debian.org/820036>, but what's the current state of Secure
Boot in Debian?

We have successfully gone through the Microsoft SHIM review process once
and are currently waiting for the review of our SHIM-13 be the
shim-review list, so we have an EV certificate and I also have some
knowledge of the process myself.

Can I (we) help with improving the situation of Secure-Boot in Debian?

Sincerely
Philipp
-- 
Philipp Hahn
Open Source Software Engineer

Univention GmbH
be open.
Mary-Somerville-Str. 1
D-28359 Bremen
Tel.: +49 421 22232-0
Fax : +49 421 22232-99
hahn@univention.de

http://www.univention.de/
Geschäftsführer: Peter H. Ganten
HRB 20755 Amtsgericht Bremen
Steuer-Nr.: 71-597-02876

[toc] | [next] | [standalone]


#59625

FromBen Hutchings <ben@decadent.org.uk>
Date2017-12-12 01:50 +0100
Message-ID<uVGVH-4d7-5@gated-at.bofh.it>
In reply to#59614

[Multipart message — attachments visible in raw view] — view raw

On Mon, 2017-12-11 at 17:55 +0100, Philipp Hahn wrote:
> Hello fellow DDs,
> 
> I'm employed by Univention and we ship our Debian based distribution
> "Univention Corporate Server" with UEFI support. Currently we're
> building our own Linux kernel and have our own signed version of shim
> and grub.
> 
> For our next release, which will be based von Debian-Stretch, we're
> considering to switch to the Debian provided kernel.
> 
> If read <https://wiki.debian.org/SecureBoot> and
> <https://bugs.debian.org/820036>, but what's the current state of Secure
> Boot in Debian?

See <https://lists.debian.org/debian-efi/2017/11/msg00021.html>.

Ben.

> We have successfully gone through the Microsoft SHIM review process once
> and are currently waiting for the review of our SHIM-13 be the
> shim-review list, so we have an EV certificate and I also have some
> knowledge of the process myself.
> 
> Can I (we) help with improving the situation of Secure-Boot in Debian?
> 
> Sincerely
> Philipp
-- 
Ben Hutchings
Unix is many things to many people,
but it's never been everything to anybody.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web