[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: EFI and multiboot2 devlopment work for Xen
From: |
Vladimir 'φ-coder/phcoder' Serbinenko |
Subject: |
Re: EFI and multiboot2 devlopment work for Xen |
Date: |
Tue, 22 Oct 2013 19:20:46 +0200 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20131005 Icedove/17.0.9 |
On 22.10.2013 19:12, Andrey Borzenkov wrote:
> В Mon, 21 Oct 2013 23:16:24 +0200
> Vladimir 'φ-coder/phcoder' Serbinenko <address@hidden> пишет:
>
>> GRUB has generic support for signing kernels/modules/whatsoever using
>> GnuPG signatures. You'd just have to ship xen.sig and kernel.sig. This
>> method doesn't have any controversy associated with EFI stuff but at
>> this particular case does exactly the same thing: verify signature.
>> multiboot2 is mainly memory structure specification so probably how the
>> files are checked is outside of its scope. But it's possible to add
>> specification on how to embed signatures in kernel.
>>
>
> I'm a bit skeptical here. Given that
>
> - EFI secure boot will still be needed to handle Windows
> - kernel can be launched directly as EFI application
> - there are other bootloaders with secure boot support
>
> distributions will likely need to carry on EFI secure boot support. At
> which point it is not clear what advantages second, parallel,
> infrastructure for the sake of single application will bring.
>
Using PE signatures is possible as I already said which invalidates your
points.
> The most compelling reason would be allowing module loading (which is
> currently disabled by secure boot patches).
>
signature.asc
Description: OpenPGP digital signature
- Re: EFI and multiboot2 devlopment work for Xen, (continued)
- Re: EFI and multiboot2 devlopment work for Xen, Konrad Rzeszutek Wilk, 2013/10/28
- Re: EFI and multiboot2 devlopment work for Xen, Vladimir 'φ-coder/phcoder' Serbinenko, 2013/10/28
- Re: EFI and multiboot2 devlopment work for Xen, Jan Beulich, 2013/10/29
- Is: Wrap-up Was: Re: EFI and multiboot2 devlopment work for Xen, Daniel Kiper, 2013/10/30
- Re: Is: Wrap-up Was: Re: EFI and multiboot2 devlopment work for Xen, Vladimir 'φ-coder/phcoder' Serbinenko, 2013/10/30
- Re: EFI and multiboot2 devlopment work for Xen, Seth Goldberg, 2013/10/28
Re: EFI and multiboot2 devlopment work for Xen, Andrey Borzenkov, 2013/10/22
- Re: EFI and multiboot2 devlopment work for Xen,
Vladimir 'φ-coder/phcoder' Serbinenko <=
Re: EFI and multiboot2 devlopment work for Xen, Daniel Kiper, 2013/10/23