AddEFISecureBootPolicyProfile should consider contents of dbx
Open
- Dominant language
- Go
- Stars
- 23
- Forks
- 29
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 2
Description
AddEFISecureBootPolicyProfile has to determine which CA certificate will be used to authenticate an image in order to compute the corresponding authentication measurement. For dual-signed binaries, it can guess incorrectly because it doesn't consider the contents of the forbidden signature database.
Contributor guide
Assessment
This issue has not been assessed yet.