canonical / canonical/secboot

WithSecureBootPolicyProfile and WithBootManagerCodeProfile should support shim's revocations.efi binary

Open
#311 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

Shim has the ability to apply SBAT revocations that are wrapped up in a separate signed PE image. We need support for this in the profile generation, as verifying the new binary will result in additional verification and measurements to PCR4 even though no code is executed.

Contributor guide

Open the contributing guide

Research direction

Start at the WithSecureBootPolicyProfile and WithBootManagerCodeProfile entry points and trace their profile-generation and verification paths. Done means both profiles support shim's signed revocations.efi PE image, including the additional verification and PCR4 measurements described in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.