Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

safeboot status command #74

Open
osresearch opened this issue Sep 24, 2020 · 2 comments · May be fixed by #87
Open

safeboot status command #74

osresearch opened this issue Sep 24, 2020 · 2 comments · May be fixed by #87
Labels
enhancement New feature or request good first issue Good for newcomers help wanted Extra attention is needed

Comments

@osresearch
Copy link
Owner

Adding a safeboot status command to report on Secure Boot configuration, platform keys, TPM config, etc would be useful to help diagnose setup and usage problems.

@osresearch osresearch added enhancement New feature or request help wanted Extra attention is needed good first issue Good for newcomers labels Sep 24, 2020
@osresearch
Copy link
Owner Author

@osresearch osresearch linked a pull request Oct 15, 2020 that will close this issue
@osresearch
Copy link
Owner Author

Things checked:

  • SecureBoot status
  • PK matches /etc/safeboot/cert.pem
  • Linux and recovery kernel images exist
  • Signature on kernels matches /etc/safeboot/cert.pem
  • efibootmgr entries
  • TPM nvram for rollback counter
  • EFI var for PCR signature
  • LUKS setup
  • TOTP setup

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request good first issue Good for newcomers help wanted Extra attention is needed
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant