Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #9890

Re: UEFI Secure Boot sprint report

From Philipp Hahn <hahn@univention.de>
Newsgroups linux.debian.project
Subject Re: UEFI Secure Boot sprint report
Date 2018-05-16 10:30 +0200
Message-ID <vPZYR-7f7-1@gated-at.bofh.it> (permalink)
References (2 earlier) <vPxzz-7gv-3@gated-at.bofh.it> <vPy2C-7wp-11@gated-at.bofh.it> <vPych-7zw-1@gated-at.bofh.it> <vPyFj-7YF-1@gated-at.bofh.it> <vPEKJ-2Zo-1@gated-at.bofh.it>
Organization Univention GmbH

Show all headers | View raw


Moin,

Am 15.05.2018 um 11:41 schrieb Steve McIntyre:
> On Tue, May 15, 2018 at 04:16:22AM +0100, Colin Watson wrote:
>> On Tue, May 15, 2018 at 11:46:00AM +0900, Hideki Yamane wrote:
>>> On Tue, 15 May 2018 03:32:26 +0100 Ben Hutchings <ben@decadent.org.uk> wrote:
>>>>>> The second point (have DAK accept ...) is part of step 7, yes.  It
>>>>>> seems to have been implemented now.
>>>>>
>>>>>  Then, remaining blocker is only template for GRUB2?
>>>>
>>>> For testing purposes, I think so.  I don't know whether GRUB implements
>>>> the policy we want at the moment.

@benh: you meat to *only* boot signed stuff and not fall back to
disabling SB before booting an unsigned kernel?
That should be addressed by
<https://salsa.debian.org/pmhahn/grub/commit/fe06193ff5a36ee6aa6a6cab12f4651b6290d91b>

>>>  Is there any issue to apply such policy to grub2 package, or just not
>>>  discussed yet?
>>
>> Either nobody's tried to discuss it with me yet or I missed the email.
>> Feel free to (preferably in the form of a patch I can review :-) ).
> 
> At / shortly after the sprint, Philipp (in CC) had patches basically
> ready for grub2, but he seems to have gone quiet. <prod>

I was busy working on our release, which took all my time.
And I'm not subscribed to debian-project.

My last work it at <https://salsa.debian.org/pmhahn/grub/tree/signing>.
In the week after the sprint I worked on GRUB2 and got it so far to have
the signed amd64 package - so at the time of writing the sprint report
GRUB2 was already ready.

I haven't yet found time to setup an UEFI-SB test environment to check
that everything works.

I haven't yet tested any other architecture != amd64.

@Colin: Please have a look at said repository above.
What I'm currently unsure about is that amd64 has those ia32 packages as
well - it should work but also untested.
My reading is that those are required for dual booting?

Philipp

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@debian.org> - 2018-04-29 21:50 +0200
  Re: UEFI Secure Boot sprint report Ian Jackson <ijackson@chiark.greenend.org.uk> - 2018-04-30 14:20 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-04-30 17:30 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-07 15:40 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-05-13 16:20 +0200
      Re: Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-14 15:10 +0200
        Re: Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 16:40 +0200
          Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:10 +0200
            Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-15 04:40 +0200
              Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:50 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-05-15 05:20 +0200
                Re: UEFI Secure Boot sprint report Steve McIntyre <steve@einval.com> - 2018-05-15 11:50 +0200
                Re: UEFI Secure Boot sprint report Philipp Hahn <hahn@univention.de> - 2018-05-16 10:30 +0200
                Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-17 01:30 +0200
                Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-06-19 01:00 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-06-19 10:30 +0200
                Re: UEFI Secure Boot - GRUB WIP report Philipp Hahn <hahn@univention.de> - 2018-06-19 11:20 +0200
                Re: UEFI Secure Boot - GRUB WIP report Colin Watson <cjwatson@debian.org> - 2018-06-19 15:00 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-10-02 14:40 +0200

csiph-web