Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shim 15.6 for CloudLinux OS 8 #251

Closed
8 tasks done
andrewlukoshko opened this issue Jun 21, 2022 · 9 comments
Closed
8 tasks done

Shim 15.6 for CloudLinux OS 8 #251

andrewlukoshko opened this issue Jun 21, 2022 · 9 comments
Labels
accepted Submission is ready for sysdev

Comments

@andrewlukoshko
Copy link

Confirm the following are included in your repo, checking each box:

  • completed README.md file with the necessary information
  • shim.efi to be signed
  • public portion of your certificate(s) embedded in shim (the file passed to VENDOR_CERT_FILE)
  • binaries, for which hashes are added to vendor_db ( if you use vendor_db and have hashes allow-listed )
  • any extra patches to shim via your own git tree or as files
  • any extra patches to grub via your own git tree or as files
  • build logs
  • a Dockerfile to reproduce the build of the provided shim EFI binaries

What is the link to your tag in a repo cloned from rhboot/shim-review?


https://github.com/cloudlinux/shim-review/tree/cloudlinux-shim-x86_64-20220621


What is the SHA256 hash of your final SHIM binary?


96dd31a8e0c9a2bb278a63be330c65b664b71b72a941e2959f8df5a596f8811a  shimia32.efi
dd2b4413b033df6a0152a2831804097a8a99e098b65de415d83807d285577ab7  shimx64.efi
@andrewlukoshko
Copy link
Author

Previous accepted shim: #152

@andrewlukoshko
Copy link
Author

@frozencemetery hello, we need security contacts verification here

@steve-mcintyre steve-mcintyre added the contact verification needed Contact verification is needed for this review label Aug 14, 2022
@steve-mcintyre
Copy link
Collaborator

verification emails sent

@andrewlukoshko
Copy link
Author

impressionism phalanges disturbs heathenish majorettes abler bounds semiprecious ungodly bragging

@steve-mcintyre
Copy link
Collaborator

steve-mcintyre commented Aug 14, 2022

Checking:

  • shim builds reproduce here
  • Cert looks OK: EV cert from Certum, expires 2024
  • signing keys in an HSM
  • SBAT data looks ok
  • minor nit in the fwupd SBAT: please add the RHEL data too if you're derived
  • 15.6, no patches
  • grub config and patches all borrowed from RHEL
  • Similar for Linux
  • old shim and grub binaries will be blocked appropriately

All looks good, just waiting on the veriffication to complete!

@andrewlukoshko
Copy link
Author

@steve-mcintyre Leonid's words:
parts warhorse métier Jeannette Buick Elbe milked soundproofs axe ravines

@steve-mcintyre
Copy link
Collaborator

all done, approved!

@steve-mcintyre steve-mcintyre added accepted Submission is ready for sysdev and removed contact verification needed Contact verification is needed for this review labels Aug 15, 2022
@andrewlukoshko
Copy link
Author

Thanks!

@andrewlukoshko
Copy link
Author

Shim is signed by MS, closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
accepted Submission is ready for sysdev
Projects
None yet
Development

No branches or pull requests

2 participants