Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Future Enh: Secure Boot support - select one or more options #7

Open
oom-is opened this issue Oct 21, 2019 · 1 comment
Open

Future Enh: Secure Boot support - select one or more options #7

oom-is opened this issue Oct 21, 2019 · 1 comment
Labels
future enhancement Enhancement that won't be worked anytime soon #sadface

Comments

@oom-is
Copy link
Owner

oom-is commented Oct 21, 2019

There are several ways to support Secure Boot; one path would be to switch to GRUB2 for the PBA bootloader but that potentially opens up additional "hard to explain/perceived" attack surface and would increase the size/complexity of the PBA image.

What's the best way to support Secure Boot with minimal changes? (See DTA Drive-Trust-Alliance#181 and DTA Drive-Trust-Alliance#301 for previous discussion.) A signed PBA image which could have appropriate keys/certs/trust anchors added to a v2.0 TPM seems the least painful - see DTA Drive-Trust-Alliance#259 for details on that approach.

@oom-is oom-is added the enhancement New feature or request label Oct 21, 2019
@oom-is oom-is assigned oom-is and unassigned oom-is Oct 21, 2019
@oom-is oom-is changed the title Secure Boot support - select one or more options Future Enh: Secure Boot support - select one or more options Oct 21, 2019
@oom-is oom-is added future enhancement Enhancement that won't be worked anytime soon #sadface and removed enhancement New feature or request labels Oct 21, 2019
@OliverO2
Copy link

See here for an easy-to-use secure boot PBA implementation based on sedutil using Grub 2: Drive-Trust-Alliance#301 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
future enhancement Enhancement that won't be worked anytime soon #sadface
Projects
None yet
Development

No branches or pull requests

2 participants