Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1569756

Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?

From Matt Fleming <matt@codeblueprint.co.uk>
Newsgroups linux.kernel
Subject Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?
Date 2017-01-30 15:00 +0100
Message-ID <t5kEW-4Ed-43@gated-at.bofh.it> (permalink)
References (5 earlier) <sM69t-68W-67@gated-at.bofh.it> <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, 30 Jan, at 12:10:29PM, David Howells wrote:
> 
> Matt argues, however, that boot_params->secure_boot should be propagated from
> the bootloader and if the bootloader wants to set it, then we should skip the
> check in efi_main() and go with the bootloader's opinion.  This is something
> we probably want to do with kexec() so that the lockdown state is propagated
> there.
 
Actually what I was arguing for was that if the boot loader wants to
set it and bypass the EFI boot stub, e.g. by going via the legacy
64-bit entry point, startup_64, then we should allow that as well as
setting the flag in the EFI boot stub.

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
  Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
    Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
      Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
    What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
      Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
        Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
          Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100

csiph-web