-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Shim 15.7 for Cisco #354
Comments
I'm not an authorized reviewer, but I'd like to contribute and help Build reproducibility
Shim source
Certificates
SBAT
GRUB@rhboot Ask for help
I'm not exactly sure how SBAT revocation works in this case. @vasudevluthra are you planning to sign upstream distros' grub binaries with your key? @rhboot do we accept this? Kernel@rhboot Ask for help
As discussed in #345, do we accept this strategy? |
@Blarse, thank you for the review. To clarify:
We recently got informed about the Microsoft exception mentioned in PR #359, so the current revision without NX support would be fine. No blame intended, as the requirements have changed in the meantime.
I'd ask Microsoft on this, if they would be willing to sign such a binary, but would also take into consideration other details, such as the hashing function used, public modulus (n) size, as well as the public exponent (e), to see if the parameters are satisfactory for reasonable usage. I'll send verification emails first, and once the verification is successful, I'll then proceed with the application. |
Verification emails sent to all the 3 contacts listed in the current application. |
dowel hicks paints Minnesotan legalize refiles lobster bagatelles |
corpuscle Dover aforesaid uppity hospitalizations announcing pertained impedance plait sprints |
@Blarse Thank you for the review. Yes, we are planning to sign upstream distros' grub binaries with our key. |
larded unbuckles Herder consorted disables phantasmagorias northerlies overdosing rotating reanimated |
Apologies for the delays, been having a lot of stuff on my plate. Please, update the issue, so it reflects the current shim 15.8. |
Thanks, We're working on it. |
Closing - please start with a new issue when you're ready, and link to this one |
Confirm the following are included in your repo, checking each box:
N/A
N/A
N/A
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/cisco/sto-uefi-secure-bootloader/releases/tag/cisco-shim-x86_64-20231116
What is the SHA256 hash of your final SHIM binary?
SHA2-256(shimx64.efi)= ead71732d1fbd7710f1aeb7c69b4ad77bfb7db7533bf5708e7c719bf0aac2df3
What is the link to your previous shim review request (if any, otherwise N/A)?
#126
#37 (accepted)
The text was updated successfully, but these errors were encountered: