canonical / canonical/secboot

AddEFISecureBootPolicyProfile should consider contents of dbx

Open
#60 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

AddEFISecureBootPolicyProfile has to determine which CA certificate will be used to authenticate an image in order to compute the corresponding authentication measurement. For dual-signed binaries, it can guess incorrectly because it doesn't consider the contents of the forbidden signature database.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.