[RFE] RPM dependencies for SecureBoot keys #9

Open
opened 2024-09-30 17:44:21 +00:00 by humaton · 0 comments
Member

Description of problem: When booting with Secure Boot, the bootloader needs to be able to recognize the certificate for the kernel/grub/etc. Right now RPM doesn't have a standardized way of indicating This bootable object needs this public key recognized for the system to boot. Version-Release number of selected component (if applicable): rpm-4.13.0.1-41.fc27 How reproducible: 100% Steps to Reproduce: 1.setup secure boot 2.build your own grub2 without the official Fedora signature 3.install new grub2 4.reboot Actual results: RPM doesn't note the new grub2 is not bootable by shim Expected results: Some sort of warning/error that the system is no longer bootable. Additional info:

Description of problem: When booting with Secure Boot, the bootloader needs to be able to recognize the certificate for the kernel/grub/etc. Right now RPM doesn't have a standardized way of indicating This bootable object needs this public key recognized for the system to boot. Version-Release number of selected component (if applicable): rpm-4.13.0.1-41.fc27 How reproducible: 100% Steps to Reproduce: 1.setup secure boot 2.build your own grub2 without the official Fedora signature 3.install new grub2 4.reboot Actual results: RPM doesn't note the new grub2 is not bootable by shim Expected results: Some sort of warning/error that the system is no longer bootable. Additional info:
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: rpms/grub2#9
No description provided.