Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #9912

Re: UEFI Secure Boot - GRUB WIP report

From Philipp Hahn <hahn@univention.de>
Newsgroups linux.debian.project
Subject Re: UEFI Secure Boot - GRUB WIP report
Date 2018-06-19 11:20 +0200
Message-ID <w2kXT-G7-3@gated-at.bofh.it> (permalink)
References (5 earlier) <vPyFj-7YF-1@gated-at.bofh.it> <vPEKJ-2Zo-1@gated-at.bofh.it> <vPZYR-7f7-1@gated-at.bofh.it> <w2bhT-2Xq-1@gated-at.bofh.it> <w2kbw-9s-11@gated-at.bofh.it>
Organization Univention GmbH

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hello,

Am 19.06.2018 um 10:25 schrieb Colin Watson:
> On Tue, Jun 19, 2018 at 07:50:15AM +0900, Hideki Yamane wrote:
>>  Just a ping question, is there any progress for grub2 package?
>>  If not, what's the blocker for it?
> 
> I had an email conversation with Philipp Hahn about this.  The main
> substance of my reply was:
> 
>   I can't easily review this as it stands because it's just so different
>   from how I manage the master branch.  Could you please rebase this onto
>   the master branch of the repository above?  Furthermore, could you make
>   sure to use git-dpm any time you're manipulating patches against
>   upstream (i.e. anything outside debian/)?  You should never need to edit
>   quilt metadata in the grub2 packaging directly.  Let me know if you need
>   help using git-dpm that isn't answered by the docs - I'm happy to
>   advise.
>   
>   Once it's in a suitable shape, I'd be happy to review by way of a merge
>   request on salsa.
> 
> I haven't yet heard back, so I assume it's taking Philipp a while to
> sort out the rebase ...

I just worked on it yesterday and have pushed my new WIP branch to salsa
just now: <https://salsa.debian.org/pmhahn/grub/tree/signing3>

My current problem is that I wanted to test the full chain: self-signed
certificates, shim, grub, Linux kernel. It uses Qemu/KVM using OVMF with
SecureBoot.
I've attached my shell script which works on my Laptop only, as my GIT
repositories are located in many places, but maybe it's useful for other
to get started.

The good news: It works: It loads the signed SHIM and GRUB.

The bad news: GRUB still falls back to loading an unsigned Linux kernel.
I suspect
<https://salsa.debian.org/pmhahn/grub/commit/448311e7374076fbd53e4c8b0f92accd04e07920>
@Luca: Any idea?

This is on my TODO list for this week, but it's not the only one.

@Colin: Please have a look if the new branch is in a suitable shape for
your consumption. Please don't merge yet until the issue mentioned above
is resolved. Thanks.

Philipp

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@debian.org> - 2018-04-29 21:50 +0200
  Re: UEFI Secure Boot sprint report Ian Jackson <ijackson@chiark.greenend.org.uk> - 2018-04-30 14:20 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-04-30 17:30 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-07 15:40 +0200
    Re: UEFI Secure Boot sprint report Tollef Fog Heen <tfheen@err.no> - 2018-05-13 16:20 +0200
      Re: Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-14 15:10 +0200
        Re: Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 16:40 +0200
          Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:10 +0200
            Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-15 04:40 +0200
              Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-05-15 04:50 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-05-15 05:20 +0200
                Re: UEFI Secure Boot sprint report Steve McIntyre <steve@einval.com> - 2018-05-15 11:50 +0200
                Re: UEFI Secure Boot sprint report Philipp Hahn <hahn@univention.de> - 2018-05-16 10:30 +0200
                Re: UEFI Secure Boot sprint report Ben Hutchings <ben@decadent.org.uk> - 2018-05-17 01:30 +0200
                Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-06-19 01:00 +0200
                Re: UEFI Secure Boot sprint report Colin Watson <cjwatson@debian.org> - 2018-06-19 10:30 +0200
                Re: UEFI Secure Boot - GRUB WIP report Philipp Hahn <hahn@univention.de> - 2018-06-19 11:20 +0200
                Re: UEFI Secure Boot - GRUB WIP report Colin Watson <cjwatson@debian.org> - 2018-06-19 15:00 +0200
  Re: UEFI Secure Boot sprint report Hideki Yamane <henrich@iijmio-mail.jp> - 2018-10-02 14:40 +0200

csiph-web