Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1569760
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? |
| Date | 2017-01-30 15:10 +0100 |
| Message-ID | <t5kOB-4Wr-13@gated-at.bofh.it> (permalink) |
| References | (7 earlier) <sYtai-an-29@gated-at.bofh.it> <t0hy2-2jl-17@gated-at.bofh.it> <t2V7X-3R1-15@gated-at.bofh.it> <t5j6b-3SD-25@gated-at.bofh.it> <t5kEW-4Ed-43@gated-at.bofh.it> |
| Organization | Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 |
Matt Fleming <matt@codeblueprint.co.uk> wrote: > > Matt argues, however, that boot_params->secure_boot should be propagated from > > the bootloader and if the bootloader wants to set it, then we should skip the > > check in efi_main() and go with the bootloader's opinion. This is something > > we probably want to do with kexec() so that the lockdown state is propagated > > there. > > Actually what I was arguing for was that if the boot loader wants to > set it and bypass the EFI boot stub, e.g. by going via the legacy > 64-bit entry point, startup_64, then we should allow that as well as > setting the flag in the EFI boot stub. That brings up another question: Should the non-EFI entry points clear the secure_boot mode flag and set a default? David
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-23 22:30 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-23 23:20 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-27 15:10 +0100
Re: [PATCH 5/8] efi: Get the secure boot status [ver #6] David Howells <dhowells@redhat.com> - 2017-01-31 15:20 +0100
What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 13:20 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-30 15:00 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? David Howells <dhowells@redhat.com> - 2017-01-30 15:10 +0100
Re: What should the default lockdown mode be if the bootloader sentinel triggers sanitization? Matt Fleming <matt@codeblueprint.co.uk> - 2017-01-31 13:00 +0100
csiph-web