WithSecureBootPolicyProfile and WithBootManagerCodeProfile should support shim's revocations.efi binary
Open
- Dominant language
- Go
- Stars
- 23
- Forks
- 29
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 2
Description
Shim has the ability to apply SBAT revocations that are wrapped up in a separate signed PE image. We need support for this in the profile generation, as verifying the new binary will result in additional verification and measurements to PCR4 even though no code is executed.
Contributor guide
Research direction
Start at the WithSecureBootPolicyProfile and WithBootManagerCodeProfile entry points and trace their profile-generation and verification paths. Done means both profiles support shim's signed revocations.efi PE image, including the additional verification and PCR4 measurements described in the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100