Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.project > #9891
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.debian.project |
| Subject | Re: UEFI Secure Boot sprint report |
| Date | 2018-05-17 01:30 +0200 |
| Message-ID | <vQe1P-7g2-3@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <vPy2C-7wp-11@gated-at.bofh.it> <vPych-7zw-1@gated-at.bofh.it> <vPyFj-7YF-1@gated-at.bofh.it> <vPEKJ-2Zo-1@gated-at.bofh.it> <vPZYR-7f7-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Wed, 2018-05-16 at 10:05 +0200, Philipp Hahn wrote: > Moin, > > Am 15.05.2018 um 11:41 schrieb Steve McIntyre: > > On Tue, May 15, 2018 at 04:16:22AM +0100, Colin Watson wrote: > > > On Tue, May 15, 2018 at 11:46:00AM +0900, Hideki Yamane wrote: > > > > On Tue, 15 May 2018 03:32:26 +0100 Ben Hutchings <ben@decadent.org.uk> wrote: > > > > > > > The second point (have DAK accept ...) is part of step 7, yes. It > > > > > > > seems to have been implemented now. > > > > > > > > > > > > Then, remaining blocker is only template for GRUB2? > > > > > > > > > > For testing purposes, I think so. I don't know whether GRUB implements > > > > > the policy we want at the moment. > > @benh: you meat to *only* boot signed stuff and not fall back to > disabling SB before booting an unsigned kernel? > That should be addressed by > <https://salsa.debian.org/pmhahn/grub/commit/fe06193ff5a36ee6aa6a6cab12f4651b6290d91b> I think that's what we agreed, yes. [...] > I haven't yet found time to setup an UEFI-SB test environment to check > that everything works. [...] It's fairly easy to do with OVMF; this blog entry summarises the process: https://www.decadent.org.uk/ben/blog/experiments-with-signed-kernels-and-modules-in-debian.html Ben. -- Ben Hutchings Teamwork is essential - it allows you to blame someone else.
Back to linux.debian.project | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@debian.org> - 2018-04-29 21:50 +0200
Re: UEFI Secure Boot sprint report Ian Jackson <ijackson@chiark.greenend.org.uk> - 2018-04-30 14:20 +0200
Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-04-30 17:30 +0200
Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-07 15:40 +0200
Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-05-13 16:20 +0200
Re: Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-14 15:10 +0200
Re: Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 16:40 +0200
Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:10 +0200
Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-15 04:40 +0200
Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:50 +0200
Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-05-15 05:20 +0200
Re: UEFI Secure Boot sprint report Steve McIntyre <steve@einval.com> - 2018-05-15 11:50 +0200
Re: UEFI Secure Boot sprint report Philipp Hahn <hahn@univention.de> - 2018-05-16 10:30 +0200
Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-17 01:30 +0200
Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-06-19 01:00 +0200
Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-06-19 10:30 +0200
Re: UEFI Secure Boot - GRUB WIP report Philipp Hahn <hahn@univention.de> - 2018-06-19 11:20 +0200
Re: UEFI Secure Boot - GRUB WIP report Colin Watson <cjwatson@debian.org> - 2018-06-19 15:00 +0200
Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-10-02 14:40 +0200
csiph-web