Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate to sbkeysync #17

Open
gdamjan opened this issue Feb 1, 2021 · 4 comments
Open

Migrate to sbkeysync #17

gdamjan opened this issue Feb 1, 2021 · 4 comments

Comments

@gdamjan
Copy link
Owner

gdamjan commented Feb 1, 2021

https://wiki.archlinux.org/index.php/Unified_Extensible_Firmware_Interface/Secure_Boot#Using_sbkeysync

sbkeysync, part of sbsigntools, is a tool to enroll the keys automatically. Alas, it assumes its own directory structure for the keys and certificates a bit different than what I did with this tool. While this tools creates all the files in /etc/secure-boot, it expects a hierarchy /etc/secureboot/keys/{db,dbx,KEK,PK}

@maximbaz
Copy link
Contributor

maximbaz commented Feb 5, 2021

Cool idea! As a heads-up, only .auth files need to go to /etc/secureboot/keys/ folder, the tool will complain if you put anything else there... 🤦‍♂️

I just went through getting rid of efitools dependency altogether in favor of tools in sbsigntools, might be useful for you as a reference: maximbaz/arch-secure-boot@485b6cf

@gdamjan
Copy link
Owner Author

gdamjan commented Feb 9, 2021

did you test sbkeysync?
it didn't work for me in a VM. I still haven't tried it on a real-metal machine.

@maximbaz
Copy link
Contributor

maximbaz commented Feb 9, 2021

Yes, I tested everything end-to-end on my laptop, it works well 👍

@gdamjan
Copy link
Owner Author

gdamjan commented Feb 22, 2021

or
systemd/systemd#18716

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants