Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-12626

Missing firmware descriptor with secureboot disabled in RHEL 8

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-8.10
    • rhel-8.8.0, rhel-8.8.0.z
    • edk2
    • edk2-20220126gitbb1bba3d77-7.el8
    • ZStream
    • rhel-sst-virtualization
    • ssg_virtualization
    • 24
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Approved Blocker
    • All
    • None

      What were you trying to do that didn't work?

      Openstack Nova fails to create VMs with secureboot disabled in a RHEL 8.8 hypervisor. This works fine in a RHEL 9 hypervisor.

      The problem is that RHEL 8.8 doesn't provide a firmware descriptor for the pc-q35-* machine type with secureboot disabled. RHEL 9 provides this configuration in the file /usr/share/qemu/firmware/50-edk2-ovmf-x64-nosb.json

      This bug is to ask for that firmware description to be included in RHEL 8.

      Please provide the package NVR for which bug is seen:

      edk2-ovmf-20220126gitbb1bba3d77-4.el8.noarch

      How reproducible:

      Always in customer environment using upstream Openstack Yoga release. Not reproduced locally.

      Steps to reproduce

      1.  
      2.  
      3.  

      Expected results

      Q35 VMs with secureboot disabled are created successfully.

      Actual results

      Q35 VMs with secureboot disabled fail to be created.

              rhn-engineering-ghoffman Gerd Hoffmann
              rhn-support-jortialc Juan Orti
              Gerd Hoffmann Gerd Hoffmann
              Xueqiang Wei Xueqiang Wei
              Votes:
              0 Vote for this issue
              Watchers:
              19 Start watching this issue

                Created:
                Updated:
                Resolved: