canonical / canonical/secboot

Check secure boot config measurements against current variable contents

Open
#538 0 comments 0 reactions 0 assignees View on GitHub
preinstall-checks
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

`checkSecureBootPolicyMeasurementsAndObtainAuthorities` checks that the secure boot config measurements (`EV_EFI_VARIABLE_DRIVER_CONFIG` events) are well formed and that their digests are correct. What it doesn't do is verify that the event data matches the actual variable contents, and it should do.

This will need an opt out flag for the post-install case in the event that they are executed after applying a signature database update, as the variable contents will be inconsistent with the log in this case.

Unit testing for this is a bit challenging right now because the code in internal/efitest to generate mock TCG logs does not currently allow the secure boot configuration contents to be customized.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.