Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1569760

Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?

From David Howells <dhowells@redhat.com>
Newsgroups linux.kernel
Subject Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization?
Date 2017-01-30 15:10 +0100
Message-ID <t5kOB-4Wr-13@gated-at.bofh.it> (permalink)
References (7 earlier) <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it> <t5kEW-4Ed-43@gated-at.bofh.it>
Organization Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903

Show all headers | View raw


Matt Fleming <matt@codeblueprint.co.uk> wrote:

> > Matt argues, however, that boot_params->secure_boot should be propagated from
> > the bootloader and if the bootloader wants to set it, then we should skip the
> > check in efi_main() and go with the bootloader's opinion.  This is something
> > we probably want to do with kexec() so that the lockdown state is propagated
> > there.
>  
> Actually what I was arguing for was that if the boot loader wants to
> set it and bypass the EFI boot stub, e.g. by going via the legacy
> 64-bit entry point, startup_64, then we should allow that as well as
> setting the flag in the EFI boot stub.

That brings up another question:  Should the non-EFI entry points clear the
secure_boot mode flag and set a default?

David

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
  Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
    Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
      Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
    What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
      Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
        Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
          Re: What should the default lockdown mode be if the bootloader  sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100

csiph-web